Unrated severityNVD Advisory· Published Apr 18, 2008· Updated Apr 23, 2026
CVE-2008-1895
CVE-2008-1895
Description
Multiple SQL injection vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to events.asp, the (2) UserName parameter to getpassword.asp, and possibly an unspecified parameter to (3) option_Update.asp in an edit action.
Affected products
6cpe:2.3:a:carboncommunities:carbon_communities:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:carboncommunities:carbon_communities:*:*:*:*:*:*:*:*range: <=2.4
- cpe:2.3:a:carboncommunities:carbon_communities:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:carboncommunities:carbon_communities:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:carboncommunities:carbon_communities:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:carboncommunities:carbon_communities:2.2:*:*:*:*:*:*:*
- cpe:2.3:a:carboncommunities:carbon_communities:2.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7News mentions
0No linked articles in our index yet.