CVE-2008-6120
NONE EPSS 60.1%
Published Feb 11, 200917y ago · Modified Jun 16, 20262w ago
Published Feb 11, 2009 17y ago
Last Modified Jun 16, 2026 2w ago
Description
SQL injection vulnerability in profile_comments.php in SocialEngine (SE) 2.7 and earlier allows remote attackers to execute arbitrary SQL commands via the comment_secure parameter.
Threat Intelligence
EPSS Exploit Probability
60.1% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-89 SQL Injection Injection
Affected Products 11
| Vendor | Product | Version | Range |
|---|---|---|---|
| socialengine | socialengine | * | ≤2.7 |
| socialengine | socialengine | 1.0 | any |
| socialengine | socialengine | 1.1 | any |
| socialengine | socialengine | 1.4 | any |
| socialengine | socialengine | 1.6 | any |
| socialengine | socialengine | 1.7 | any |
| socialengine | socialengine | 1.8 | any |
| socialengine | socialengine | 2.0 | any |
| socialengine | socialengine | 2.0 | any |
| socialengine | socialengine | 2.1 | any |
| socialengine | socialengine | 2.4 | any |
References 3
- marc.info http://marc.info/?l=bugtraq&m=122720734728665&w=2
- securityfocus.com http://www.securityfocus.com/bid/32382
- exchange.xforce.ibmcloud.com https://exchange.xforce.ibmcloud.com/vulnerabilities/46770
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.