Vulnerability Description
Multiple SQL injection vulnerabilities in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allow remote attackers to execute arbitrary SQL commands via (1) the f parameter in a showforum action, (2) the u parameter in a profile action, (3) the viewcat parameter, or (4) a combination of scb_uid and scb_ident cookie values.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Scssboard | Scssboard | 1.0 |
Related Weaknesses (CWE)
References
- http://securityreason.com/securityalert/4739
- http://www.securityfocus.com/bid/27866
- https://www.exploit-db.com/exploits/5149
- http://securityreason.com/securityalert/4739
- http://www.securityfocus.com/bid/27866
- https://www.exploit-db.com/exploits/5149
FAQ
What is CVE-2008-5578?
CVE-2008-5578 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple SQL injection vulnerabilities in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allow remote attackers to execute arbitrary SQL commands via (1) the f parameter in a showforum action, (2) th...
How severe is CVE-2008-5578?
CVE-2008-5578 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-5578?
Check the references section above for vendor advisories and patch information. Affected products include: Scssboard Scssboard.