Vulnerability Description
SQL injection vulnerability in includes/functions/banners-external.php in phpBP 2 RC3 (2.204) FIX 4 allows remote attackers to execute arbitrary SQL commands via the id parameter in a banner_out action.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpbp | Phpbp | rc3_2.204 |
Related Weaknesses (CWE)
References
- http://irk4z.wordpress.com/2008/03/16/phpbp-rc3-2204-fix4-remote-sql-injection-v
- http://secunia.com/advisories/29411Vendor Advisory
- http://www.phpbp.com/filedownload-phpbp2-RC3-204-fix5_22.htmlURL Repurposed
- http://www.securityfocus.com/bid/28272
- http://www.vupen.com/english/advisories/2008/0910/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41222
- https://www.exploit-db.com/exploits/5263
- http://irk4z.wordpress.com/2008/03/16/phpbp-rc3-2204-fix4-remote-sql-injection-v
- http://secunia.com/advisories/29411Vendor Advisory
- http://www.phpbp.com/filedownload-phpbp2-RC3-204-fix5_22.htmlURL Repurposed
- http://www.securityfocus.com/bid/28272
- http://www.vupen.com/english/advisories/2008/0910/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41222
- https://www.exploit-db.com/exploits/5263
FAQ
What is CVE-2008-1408?
CVE-2008-1408 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL injection vulnerability in includes/functions/banners-external.php in phpBP 2 RC3 (2.204) FIX 4 allows remote attackers to execute arbitrary SQL commands via the id parameter in a banner_out actio...
How severe is CVE-2008-1408?
CVE-2008-1408 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-1408?
Check the references section above for vendor advisories and patch information. Affected products include: Phpbp Phpbp.