First published: Fri Apr 10 2009(Updated: )
SQL injection vulnerability in CoolURI (cooluri) 1.0.11 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TYPO3 | ||
CoolURI | <=1.0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6686 has a high severity due to its SQL injection vulnerability allowing remote execution of arbitrary SQL commands.
To fix CVE-2008-6686, upgrade the CoolURI extension to version 1.0.12 or later.
CVE-2008-6686 affects CoolURI versions 1.0.11 and earlier for TYPO3.
Yes, CVE-2008-6686 can be exploited remotely by attackers to execute arbitrary SQL commands.
The primary mitigation for CVE-2008-6686 is to update to a patched version of the CoolURI extension.