CVE-2006-7247: SQL Injection
Published Sep 6, 2012
·Updated
SQL injection vulnerability in the Weblinks (comweblinks) component for Joomla! and Mambo 1.0.9 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter.
Affected Software
3 affected components
Joomla Com Weblinks<=1.0.9
Joomla Joomla\!
Mambo-foundation Mambo
Event History
Sep 6, 2012
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
07:55 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-7247?
CVE-2006-7247 has a moderate severity rating due to its potential for allowing remote SQL injection attacks.
2
How do I fix CVE-2006-7247?
To fix CVE-2006-7247, update the Joomla! com_weblinks component to a version higher than 1.0.9.
3
What software is affected by CVE-2006-7247?
CVE-2006-7247 affects Joomla! versions 1.0.9 and earlier, as well as the com_weblinks component.
4
Can CVE-2006-7247 be exploited remotely?
Yes, CVE-2006-7247 can be exploited remotely by attackers through the title parameter.
5
Is there a workaround for CVE-2006-7247?
A temporary workaround for CVE-2006-7247 is to validate and sanitize input data before processing.