Back to Database
Status published
Medium
CVE-2008-0129
SQL injection vulnerability in starnet/addons/slideshow_full.php in Site@School 2.3.10 and earlier...
Vulnerability Description
SQL injection vulnerability in starnet/addons/slideshow_full.php in Site@School 2.3.10 and earlier allows remote attackers to execute arbitrary SQL commands via the album_name parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-0129
Credits & Attribution
No credits recorded in the NVD database.
References
More from siteatschool
View All →CVE-2007-3276
Cross-site scripting (XSS) vulnerability in index.php in Site@School (S@S) 2.4.10...
Medium
4.3
CVE-2006-4922
Unrestricted file upload vulnerability in starnet/editors/htmlarea/popups/images.php in Site@School (S@S) 2.4.02...
Medium
5
CVE-2006-4921
PHP remote file inclusion vulnerability in Site@School (S@S) 2.4.03 and...
High
7.5
CVE-2006-4920
Multiple PHP remote file inclusion vulnerabilities in Site@School (S@S) 2.4.02...
High
7.5
CVE-2006-4919
Directory traversal vulnerability in starnet/editors/htmlarea/popups/images.php in Site@School (S@S) 2.4.02 and...
Low
2.6
Affected Vendor
siteatschool
View all reports →Affected Software
siteatschool
Vulnerable Versions:
0
Timeline
Official Publish:
January 8th, 2008
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.