CVE-2008-1895
Summary
| CVE | CVE-2008-1895 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-04-18 22:05:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Multiple SQL injection vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to events.asp, the (2) UserName parameter to getpassword.asp, and possibly an unspecified parameter to (3) option_Update.asp in an edit action. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Carboncommunities | Carbon Communities | 1.0 | All | All | All |
| Application | Carboncommunities | Carbon Communities | 1.1 | All | All | All |
| Application | Carboncommunities | Carbon Communities | 2.1 | All | All | All |
| Application | Carboncommunities | Carbon Communities | 2.2 | All | All | All |
| Application | Carboncommunities | Carbon Communities | 2.3 | All | All | All |
| Application | Carboncommunities | Carbon Communities | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Carbon Communities forum Multiple Vulnerabilities. | af854a3a-2127-422b-91ae-364da2661108 | bugreport.ir | Exploit |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| carbon communities <= 2.4 - Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| Carbon Communities Multiple SQL Injection and Cross-Site Scripting Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| BugReport.ir - Security Advisory - Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | bugreport.ir | Exploit |
| Carbon Communities Cross-Site Scripting and SQL Injection - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.