First published: Wed Aug 01 2007(Updated: )
SQL injection vulnerability in index.php in the Firestorm Technologies GMaps (com_gmaps) 1.00 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mapId parameter in a viewmap action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firestorm Technologies GMaps | =1.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4128 is considered a critical vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2007-4128, you should upgrade to a patched version of the Firestorm Technologies GMaps component that addresses this SQL injection vulnerability.
Exploiting CVE-2007-4128 can allow attackers to manipulate the database, leading to unauthorized data access, data loss, or complete control of the affected Joomla! website.
CVE-2007-4128 affects the Firestorm Technologies GMaps component version 1.00 for Joomla!.
You can detect CVE-2007-4128 by testing the viewmap action with unsanitized input for the mapId parameter to see if it allows SQL command execution.