First published: Thu Jul 02 2009(Updated: )
Multiple SQL injection vulnerabilities in affiliates.php in the Affiliation (aka Affiliates) module 1.1.0 and earlier for PunBB allow remote attackers to execute arbitrary SQL commands via the (1) in or (2) out parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PunBB | ||
Punres Affiliates Mod | <=1.1.0 | |
Punres Affiliates Mod | =1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2308 is considered a high severity vulnerability due to its potential for remote SQL command execution.
To fix CVE-2009-2308, update the Punres Affiliates module to a version higher than 1.1.0.
CVE-2009-2308 affects all versions of the Affiliates module up to and including 1.1.0.
CVE-2009-2308 is an SQL injection vulnerability that allows arbitrary SQL command execution.
Yes, CVE-2009-2308 can be exploited remotely by attackers through crafted HTTP requests.