First published: Wed Nov 23 2005(Updated: )
Multiple SQL injection vulnerabilities in Joomla! before 1.0.4 allow remote attackers to execute arbitrary SQL commands via the (1) Itemid variable in the Polls modules and (2) multiple unspecified methods in the mosDBTable class.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | =1.0 | |
Joomla | =1.0.1 | |
Joomla | =1.0.2 | |
Joomla | =1.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3772 has a medium severity level due to the potential for remote SQL execution leading to data compromise.
To fix CVE-2005-3772, upgrade Joomla! to version 1.0.4 or later where the vulnerabilities are addressed.
CVE-2005-3772 affects Joomla! versions 1.0, 1.0.1, 1.0.2, and 1.0.3.
Yes, CVE-2005-3772 can be exploited remotely by attackers to execute arbitrary SQL commands.
CVE-2005-3772 involves vulnerabilities in the Polls module and the mosDBTable class.