Name | CVE-2008-2231 |
Description | SQL injection vulnerability in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) R_2_5_0_94 and earlier allows remote attackers to execute SQL commands and read table information via the id parameter. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-1633-1 |
Debian Bugs | 484499 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
slash | source | etch | 2.2.6-8etch1 | DSA-1633-1 | ||
slash | source | (unstable) | (unfixed) | medium | 484499 |
See CVE-2008-2553
maintainer wants to remove package from unstable and move to experimental