First published: Mon Jul 10 2006(Updated: )
Multiple SQL injection vulnerabilities in Joomla! before 1.0.10 allow remote attackers to execute arbitrary SQL commands via unspecified parameters involving the (1) "Remember Me" function, (2) "Related Items" module, and the (3) "Weblinks submission".
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | =1.0 | |
Joomla | =1.0.1 | |
Joomla | =1.0.2 | |
Joomla | =1.0.3 | |
Joomla | =1.0.4 | |
Joomla | =1.0.5 | |
Joomla | =1.0.7 | |
Joomla | =1.0.8 | |
Joomla | =1.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3481 is considered to have a high severity due to its potential for remote SQL injection attacks.
To fix CVE-2006-3481, you should upgrade Joomla! to version 1.0.10 or later, which addresses the vulnerabilities.
CVE-2006-3481 affects the "Remember Me" function, the "Related Items" module, and the "Weblinks submission" components in Joomla!.
Yes, CVE-2006-3481 can be exploited remotely by attackers to execute arbitrary SQL commands.
Yes, all Joomla! versions prior to 1.0.10 are vulnerable to CVE-2006-3481.