First published: Thu Aug 23 2007(Updated: )
SQL injection vulnerability in index.php in the EventList component (com_eventlist) 0.8 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the did parameter in a details action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Eventlist | <=0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-4509 is considered high due to the potential for remote SQL injection attacks that can compromise the database.
To fix CVE-2007-4509, upgrade the Joomla Eventlist component to version 0.9 or later, which addresses the SQL injection vulnerability.
Exploiting CVE-2007-4509 can allow attackers to execute arbitrary SQL commands, potentially leading to data loss, corruption, or unauthorized access.
CVE-2007-4509 affects Joomla Eventlist component versions 0.8 and earlier.
Yes, CVE-2007-4509 can often be detected during a security audit by testing for SQL injection vulnerabilities in the affected parameters.