CVE-2008-6866: SQL Injection
SQL injection vulnerability in modules.php in the CurrentIssue module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a summary action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6866?
CVE-2008-6866 is classified as a high severity vulnerability due to its potential for remote exploitation and arbitrary SQL command execution.
How do I fix CVE-2008-6866?
To fix CVE-2008-6866, upgrade to the latest version of the Current_Issue module for PHP-Nuke that addresses this SQL injection vulnerability.
Who is affected by CVE-2008-6866?
Any users of the Current_Issue module for PHP-Nuke that do not have the security patch applied are susceptible to CVE-2008-6866.
What type of vulnerability is CVE-2008-6866?
CVE-2008-6866 is an SQL injection vulnerability that allows attackers to manipulate database queries.
What can attackers do with CVE-2008-6866?
Attackers can execute arbitrary SQL commands on the database of affected PHP-Nuke installations, potentially leading to data breaches.