CVE detail
CVE-2008-6049 — CVE-2008-6049
Published 2009-02-04 · Modified 2023-11-07 · Source nvd
UNKNOWN
severity
CVSS-derived band
—
EPSS probability
exploitation probability, 30d
—
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Rejected reason: SQL injection vulnerability in index.php in TinyMCE 2.0.1 allows remote attackers to execute arbitrary SQL commands via the menuID parameter. NOTE: CVE and multiple reliable third parties dispute this issue, since TinyMCE does not contain index.php or any PHP code. This may be an issue in a product that has integrated TinyMCE
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References