Unrated severityNVD Advisory· Published Feb 16, 2009· Updated Apr 23, 2026
CVE-2008-6145
CVE-2008-6145
Description
Multiple SQL injection vulnerabilities in the WEC Discussion Forum (wec_discussion) extension 1.7.0 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected products
6cpe:2.3:a:typo3:wec_discussion_forum:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:typo3:wec_discussion_forum:*:*:*:*:*:*:*:*range: <=1.7.0
- cpe:2.3:a:typo3:wec_discussion_forum:1.6:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:wec_discussion_forum:1.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:wec_discussion_forum:1.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:wec_discussion_forum:1.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:wec_discussion_forum:1.6.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- typo3.org/teams/security/security-bulletins/typo3-20081222-2nvdPatchVendor Advisory
- secunia.com/advisories/33254nvdVendor Advisory
- typo3.org/extensions/repository/view/wec_discussion/1.7.1nvd
- www.vupen.com/english/advisories/2008/3502nvd
News mentions
0No linked articles in our index yet.