CVE-2008-6255
Last modified
CVE-2008-6255 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in vBulletin 3.7.4 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) answer parameter to admincp/verify.php, (2) extension parameter in an edit action to admincp/attachmentpermission.php, and the (3) iperm parameter to admincp/image.php.. EPSS estimates a 0.90% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in vBulletin 3.7.4 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) answer parameter to admincp/verify.php, (2) extension parameter in an edit action to admincp/attachmentpermission.php, and the (3) iperm parameter to admincp/image.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vbulletin | Vbulletin | 3.7.4 |
References
- http://secunia.com/advisories/32775Vendor Advisory
- http://secunia.com/advisories/32775Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-6255?
How severe is CVE-2008-6255?
How do I fix CVE-2008-6255?
Are you affected by CVE-2008-6255?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
