CVE-2008-6692: SQL Injection
Published Apr 10, 2009
·Updated
SQL injection vulnerability in Diocese of Portsmouth Training Courses (pdtrainingcourses) extension 0.1.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
Affected Software
2 affected components
Typo3 TYPO3
Fr.simon Rundell Pd Trainingcourses=0.1.1
Event History
Apr 10, 2009
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
10:00 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-6692?
CVE-2008-6692 is classified as a moderate severity SQL injection vulnerability.
2
How do I fix CVE-2008-6692?
To fix CVE-2008-6692, update the Diocese of Portsmouth Training Courses extension to the latest version that addresses the SQL injection issue.
3
What types of attacks can CVE-2008-6692 facilitate?
CVE-2008-6692 can facilitate remote attackers in executing arbitrary SQL commands against the database.
4
Which software versions are affected by CVE-2008-6692?
CVE-2008-6692 affects the Diocese of Portsmouth Training Courses extension version 0.1.1 for TYPO3.
5
What system is primarily impacted by CVE-2008-6692?
CVE-2008-6692 primarily impacts websites using TYPO3 with the vulnerable pd_trainingcourses extension.