Vulnerability Description
SQL injection vulnerability in joke.php in Jokes Complete Website 2.1.3 allows remote attackers to execute arbitrary SQL commands via the jokeid parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Easysitenetwork | Jokes Complete Website | 2.1.3 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/30860Vendor Advisory
- http://securityreason.com/securityalert/4613
- http://www.securityfocus.com/bid/29968
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43425
- https://www.exploit-db.com/exploits/5948
- http://secunia.com/advisories/30860Vendor Advisory
- http://securityreason.com/securityalert/4613
- http://www.securityfocus.com/bid/29968
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43425
- https://www.exploit-db.com/exploits/5948
FAQ
What is CVE-2008-5174?
CVE-2008-5174 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL injection vulnerability in joke.php in Jokes Complete Website 2.1.3 allows remote attackers to execute arbitrary SQL commands via the jokeid parameter.
How severe is CVE-2008-5174?
CVE-2008-5174 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-5174?
Check the references section above for vendor advisories and patch information. Affected products include: Easysitenetwork Jokes Complete Website.