Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-7267

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2008-7267
Last Modified 01 Dec 2010 12:00:00
Published 01 Dec 2010 11:06:12
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2008-7267

Summary

SQL injection vulnerability in announcements.php in SiteEngine 5.x allows remote attackers to execute arbitrary SQL commands via the id parameter.

Vulnerable Systems

Application

  • Boka Siteengine 5.0


References

BID - 31889

BUGTRAQ - 20081023 SiteEngine 5.x Multiple Remote Vulnerabilities

MILW0RM - 6823

SECUNIA - 32404


Last Updated: 27 May 2016 10:49:32