Kutubisitte · Kutub-I Sitte · CVE-2008-1219
**Name of the Vulnerable Software and Affected Versions**
Kutub-i Sitte (KutubiSitte) version 1.1
**Description**
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved by exploiting the `kid` parameter in a `hadisgoster` action to `modules.php`.
**Recommendations**
For Kutub-i Sitte (KutubiSitte) version 1.1, consider restricting access to the `modules.php` endpoint, specifically the `hadisgoster` action, to minimize the risk of exploitation. Avoid using the `kid` parameter in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.