SQL Injection Vulnerability in Stash 1.0.3 by Stash
CVE-2008-4080

Currently unrated

Key Information:

Vendor

Stash

Status
Vendor
CVE Published:
15 September 2008

What is CVE-2008-4080?

An SQL injection vulnerability exists in Stash version 1.0.3, where the absence of magic_quotes_gpc allows attackers to manipulate SQL queries. This can lead to remote attackers executing arbitrary SQL commands through the 'username' parameter in admin/library/authenticate.php and the 'download' parameter in downloadmp3.php. Proper sanitization and validation of user inputs are critical to mitigating these vulnerabilities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.