CVE-2008-6649: SQL Injection
SQL injection vulnerability in manager/imagedetailseditor.php in Ktools PhotoStore 2.5, 2.9.8, 3.1.0, and other versions through 3.5.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6649?
CVE-2008-6649 is rated as a medium severity SQL injection vulnerability allowing execution of arbitrary SQL commands.
How do I fix CVE-2008-6649?
To fix CVE-2008-6649, it is recommended to validate and sanitize the 'id' parameter in the manager/image_details_editor.php script.
Which versions of Ktools PhotoStore are affected by CVE-2008-6649?
CVE-2008-6649 affects Ktools PhotoStore versions 2.5, 2.9.8, 3.1.0, through 3.5.2.
Can I exploit CVE-2008-6649 to gain unauthorized access?
Yes, attackers can exploit CVE-2008-6649 to execute unauthorized SQL commands against the database.
Is CVE-2008-6649 a known vulnerability?
Yes, CVE-2008-6649 is a publicly known SQL injection vulnerability and has been documented in multiple security advisories.