CVE-2007-4456: SQL Injection
SQL injection vulnerability in index.php in the SimpleFAQ (comsimplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrary SQL commands via the aid parameter. NOTE: it was later reported that 2.40 is also affected, and that the component can be used in Joomla! in addition to Mambo.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4456?
CVE-2007-4456 is classified as a medium severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2007-4456?
To fix CVE-2007-4456, upgrade the SimpleFAQ component to a patched version or apply necessary filters to sanitize user input in the 'aid' parameter.
Which versions of SimpleFAQ are affected by CVE-2007-4456?
CVE-2007-4456 affects SimpleFAQ versions 2.11 and 2.40.
Is CVE-2007-4456 exploitable on Joomla?
Yes, CVE-2007-4456 is also exploitable in Joomla! when using the SimpleFAQ component.
What component is vulnerable in CVE-2007-4456?
CVE-2007-4456 exploits a vulnerability in the SimpleFAQ (com_simplefaq) component for Mambo.