First published: Tue Aug 21 2007(Updated: )
SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrary SQL commands via the aid parameter. NOTE: it was later reported that 2.40 is also affected, and that the component can be used in Joomla! in addition to Mambo.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mambo (MamboCMS) | ||
Parkview Consultants SimpleFAQ | =2.11 | |
Parkview Consultants SimpleFAQ | =2.40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4456 is classified as a medium severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2007-4456, upgrade the SimpleFAQ component to a patched version or apply necessary filters to sanitize user input in the 'aid' parameter.
CVE-2007-4456 affects SimpleFAQ versions 2.11 and 2.40.
Yes, CVE-2007-4456 is also exploitable in Joomla! when using the SimpleFAQ component.
CVE-2007-4456 exploits a vulnerability in the SimpleFAQ (com_simplefaq) component for Mambo.