CVE-2008-4711
Last modified
CVE-2008-4711 is a vulnerability of currently unknown severity. SQL injection vulnerability in Joovili 3.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.blog.php, (2) view.event.php, (3) view.group.php, (4) view.music.php, (5) view.picture.php, and (6) view.video.php.. EPSS estimates a 0.91% chance of exploitation in the next 30 days.
Description
SQL injection vulnerability in Joovili 3.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.blog.php, (2) view.event.php, (3) view.group.php, (4) view.music.php, (5) view.picture.php, and (6) view.video.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Joovili | Joovili | <= 3.0 |
| Joovili | Joovili | 2.1 |
| Joovili | Joovili | 3.0.6 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-4711?
How severe is CVE-2008-4711?
How do I fix CVE-2008-4711?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-4705SQL injection vulnerability in success_story.php in php Onli…
- CVE-2008-4706SQL injection vulnerability in VBGooglemap Hotspot Edition 1…
- CVE-2008-4707Directory traversal vulnerability in index.php in BbZL.PhP 0…
- CVE-2008-4708BbZL.PhP 0.92 allows remote attackers to bypass authenticati…
- CVE-2008-4709SQL injection vulnerability in news_read.php in Pilot Group …
- CVE-2008-4710Cross-site scripting (XSS) vulnerability in the stock quotes…
- CVE-2008-4712Directory traversal vulnerability in pages/showblog.php in L…
- CVE-2008-4713SQL injection vulnerability in view.php in 212cafe Board 0.0…
- CVE-2008-4714Atomic Photo Album 1.1.0 pre4 does not properly handle the a…
- CVE-2008-4715SQL injection vulnerability in the Jpad (com_jpad) 1.0 compo…
- CVE-2008-4716SQL injection vulnerability in show.php in BitmixSoft PHP-La…
- CVE-2008-4717SQL injection vulnerability in bannerclick.php in ZEELYRICS …
Are you affected by CVE-2008-4711?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
