CVE-2008-6475

SQL injection vulnerability in the guestbook component (components/guestbook/guestbook.php) in Drake CMS 0.4.11 and earlier allows remote attackers to execute arbitrary SQL commands via the Via HTTP header (HTTP_VIA) to index.php.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 54%
VendorProductVersion
drake_teamdrake_cms
𝑥
≤ 0.2.2.846
drake_teamdrake_cms
𝑥
≤ 0.2.2_alpha_rev.846
drake_teamdrake_cms
𝑥
≤ 0.3.2
drake_teamdrake_cms
𝑥
≤ 0.3.3
drake_teamdrake_cms
𝑥
≤ 0.3.4b
drake_teamdrake_cms
𝑥
≤ 0.3.5
drake_teamdrake_cms
𝑥
≤ 0.3.6
drake_teamdrake_cms
𝑥
≤ 0.3.7
drake_teamdrake_cms
𝑥
≤ 0.3.7_beta
drake_teamdrake_cms
𝑥
≤ 0.3.8_beta
drake_teamdrake_cms
𝑥
≤ 0.3.9
drake_teamdrake_cms
𝑥
≤ 0.4.0
drake_teamdrake_cms
𝑥
≤ 0.4.0b
drake_teamdrake_cms
𝑥
≤ 0.4.1
drake_teamdrake_cms
𝑥
≤ 0.4.10_rc6
drake_teamdrake_cms
𝑥
≤ 0.4.11
drake_teamdrake_cms
0.2
𝑥
= Vulnerable software versions