Unrated severityNVD Advisory· Published Sep 30, 2008· Updated Apr 23, 2026
CVE-2008-4338
CVE-2008-4338
Description
SQL injection vulnerability in the brilliant_gallery_checklist_save function in the bgchecklist/save script in Brilliant Gallery 5.x and 6.x, a module for Drupal, allows remote authenticated users with "access brilliant_gallery" permissions to execute arbitrary SQL commands via the (1) nid, (2) qid, (3) state, and possibly (4) user parameters.
Affected products
3cpe:2.3:a:vacilanda:brilliant_gallery:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:vacilanda:brilliant_gallery:*:*:*:*:*:*:*:*
- cpe:2.3:a:vacilanda:brilliant_gallery:5:*:*:*:*:*:*:*
- cpe:2.3:a:vacilanda:brilliant_gallery:6:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- lists.grok.org.uk/pipermail/full-disclosure/2008-September/064662.htmlnvdExploit
- www.securityfocus.com/bid/31387nvdExploit
- secunia.com/advisories/32015nvdVendor Advisory
- drupal.org/node/313054nvd
- securityreason.com/securityalert/4338nvd
- www.securityfocus.com/archive/1/496726/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/45411nvd
News mentions
0No linked articles in our index yet.