First published: Fri Jan 19 2007(Updated: )
SQL injection vulnerability in (1) Joomla! 1.0.11 and 1.5 Beta, and (2) Mambo 4.6.1, allows remote attackers to execute arbitrary SQL commands via the id parameter when cancelling content editing.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | =1.0.11 | |
Joomla | =1.5.0_beta | |
Mambo (MamboCMS) | =4.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0374 has a moderate severity rating due to the potential for remote SQL injection attacks.
To fix CVE-2007-0374, upgrade Joomla! to version 1.0.12 or later, or Mambo to a patched version.
CVE-2007-0374 affects Joomla! versions 1.0.11 and 1.5 Beta, as well as Mambo version 4.6.1.
CVE-2007-0374 is associated with SQL injection attacks, which allow attackers to execute arbitrary SQL commands.
To determine if your site is vulnerable to CVE-2007-0374, check if you are using an affected version of Joomla! or Mambo and test for SQL injection.