CVE-2008-4651
Last modified
CVE-2008-4651 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby parameter to admin/cms/images.php and the (2) nav_id parameter in an editrecord action to admin/cms/nav.php.. EPSS estimates a 0.80% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby parameter to admin/cms/images.php and the (2) nav_id parameter in an editrecord action to admin/cms/nav.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jetbox | Jetbox Cms | 2.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-4651?
How severe is CVE-2008-4651?
How do I fix CVE-2008-4651?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-4645plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 a…
- CVE-2008-4646The Websense Reporter Module in Websense Enterprise 6.3.2 st…
- CVE-2008-4647SQL injection vulnerability in index.php in sweetCMS 1.5.2 a…
- CVE-2008-4648Cross-site scripting (XSS) vulnerability in index.php in Elx…
- CVE-2008-4649Session fixation vulnerability in Elxis CMS 2008.1 revision …
- CVE-2008-4650SQL injection vulnerability in viewevent.php in myEvent 1.6 …
- CVE-2008-4652Buffer overflow in the ActiveX control (DartFtp.dll) in Dart…
- CVE-2008-4653SQL injection vulnerability in makale.php in Makale 0.26 and…
- CVE-2008-4654Stack-based buffer overflow in the parse_master function in …
- CVE-2008-4655SQL injection vulnerability in the Simple survey (simplesurv…
- CVE-2008-4656SQL injection vulnerability in the Frontend Users View (feus…
- CVE-2008-4657SQL injection vulnerability in the Econda Plugin (econda) 0.…
Are you affected by CVE-2008-4651?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
