Vulnerability CVE-2008-5768


Published: 2008-12-30   Modified: 2012-02-13

Description:
SQL injection vulnerability in print.php in the AM Events (aka Amevents) module 0.22 for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.

See advisories in our WLB2 database:
Topic
Author
Date
High
XOOPS Module Amevents (print.php id) SQL Injection Vulnerability
netRoot
04.01.2009

Type:

CWE-89

(Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Sirium -> Am events module 

 References:
http://xforce.iss.net/xforce/xfdb/47360
http://www.securityfocus.com/bid/32848
http://www.milw0rm.com/exploits/7479
http://securityreason.com/securityalert/4854

Copyright 2021, cxsecurity.com

 

Back to Top