First published: Thu Sep 06 2012(Updated: )
SQL injection vulnerability in the Weblinks (com_weblinks) component for Joomla! and Mambo 1.0.9 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | <=1.0.9 | |
Joomla | ||
Mambo |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-7247 has a moderate severity rating due to its potential for allowing remote SQL injection attacks.
To fix CVE-2006-7247, update the Joomla! com_weblinks component to a version higher than 1.0.9.
CVE-2006-7247 affects Joomla! versions 1.0.9 and earlier, as well as the com_weblinks component.
Yes, CVE-2006-7247 can be exploited remotely by attackers through the title parameter.
A temporary workaround for CVE-2006-7247 is to validate and sanitize input data before processing.