ID

VAR-200902-0192


CVE

CVE-2008-6086


TITLE

Camera Life of album.php In SQL Injection vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2009-002814

DESCRIPTION

SQL injection vulnerability in album.php in Camera Life 2.6.2b4 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3355. Camera Life is prone to an SQL-injection vulnerability and a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data. Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. Camera Life 2.6.2b4 is affected; other versions may also be vulnerable. Camera Life is an open source PHP-based photo management and organization plugin

Trust: 1.98

sources: NVD: CVE-2008-6086 // JVNDB: JVNDB-2009-002814 // BID: 31689 // VULHUB: VHN-36211

AFFECTED PRODUCTS

vendor:camera lifemodel:camera lifescope:eqversion:2.6.2b4

Trust: 2.4

vendor:cameramodel:life camera life 2.6.2b4scope: - version: -

Trust: 0.3

sources: BID: 31689 // JVNDB: JVNDB-2009-002814 // CNNVD: CNNVD-200902-132 // NVD: CVE-2008-6086

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2008-6086
value: HIGH

Trust: 1.0

NVD: CVE-2008-6086
value: HIGH

Trust: 0.8

CNNVD: CNNVD-200902-132
value: HIGH

Trust: 0.6

VULHUB: VHN-36211
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2008-6086
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-36211
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-36211 // JVNDB: JVNDB-2009-002814 // CNNVD: CNNVD-200902-132 // NVD: CVE-2008-6086

PROBLEMTYPE DATA

problemtype:CWE-89

Trust: 1.9

sources: VULHUB: VHN-36211 // JVNDB: JVNDB-2009-002814 // NVD: CVE-2008-6086

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200902-132

TYPE

SQL injection

Trust: 0.6

sources: CNNVD: CNNVD-200902-132

CONFIGURATIONS

sources: JVNDB: JVNDB-2009-002814

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-36211

PATCH

title:Top Pageurl:http://fdcl.sourceforge.net/

Trust: 0.8

sources: JVNDB: JVNDB-2009-002814

EXTERNAL IDS

db:NVDid:CVE-2008-6086

Trust: 2.8

db:BIDid:31689

Trust: 2.0

db:EXPLOIT-DBid:6710

Trust: 1.7

db:JVNDBid:JVNDB-2009-002814

Trust: 0.8

db:MILW0RMid:6710

Trust: 0.6

db:XFid:45803

Trust: 0.6

db:CNNVDid:CNNVD-200902-132

Trust: 0.6

db:SEEBUGid:SSVID-65819

Trust: 0.1

db:VULHUBid:VHN-36211

Trust: 0.1

sources: VULHUB: VHN-36211 // BID: 31689 // JVNDB: JVNDB-2009-002814 // CNNVD: CNNVD-200902-132 // NVD: CVE-2008-6086

REFERENCES

url:http://www.securityfocus.com/bid/31689

Trust: 1.7

url:http://sourceforge.net/project/shownotes.php?group_id=70910&release_id=643552

Trust: 1.6

url:https://www.exploit-db.com/exploits/6710

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/45803

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2008-6086

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2008-6086

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/45803

Trust: 0.6

url:http://www.milw0rm.com/exploits/6710

Trust: 0.6

url:http://fdcl.sourceforge.net/

Trust: 0.3

url:http://sourceforge.net/project/shownotes.php?group_id=70910&release_id=643552

Trust: 0.1

sources: VULHUB: VHN-36211 // BID: 31689 // JVNDB: JVNDB-2009-002814 // CNNVD: CNNVD-200902-132 // NVD: CVE-2008-6086

CREDITS

BackDoor

Trust: 0.9

sources: BID: 31689 // CNNVD: CNNVD-200902-132

SOURCES

db:VULHUBid:VHN-36211
db:BIDid:31689
db:JVNDBid:JVNDB-2009-002814
db:CNNVDid:CNNVD-200902-132
db:NVDid:CVE-2008-6086

LAST UPDATE DATE

2025-04-10T23:15:39.095000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-36211date:2017-09-29T00:00:00
db:BIDid:31689date:2015-05-07T17:22:00
db:JVNDBid:JVNDB-2009-002814date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200902-132date:2009-02-09T00:00:00
db:NVDid:CVE-2008-6086date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-36211date:2009-02-06T00:00:00
db:BIDid:31689date:2008-10-09T00:00:00
db:JVNDBid:JVNDB-2009-002814date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200902-132date:2009-02-06T00:00:00
db:NVDid:CVE-2008-6086date:2009-02-06T19:30:00.437