CVE-2007-4777: SQL Injection
Published Sep 10, 2007
·Updated
SQL injection vulnerability in Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to the archive section. NOTE: this may be the same as CVE-2007-4778.
Affected Software
3 affected components
Joomla joomla=1.5.0_rc1
Joomla joomla=1.5.0_beta2
Joomla joomla=1.5.0_beta
Remediation
Patch Available
Patch Available
Event History
Sep 10, 2007
CVE Published
09:17 PM
Sep 11, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4777?
CVE-2007-4777 has a severity rating that reflects its potential to allow remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2007-4777?
To fix CVE-2007-4777, it is recommended to upgrade Joomla! to version 1.5 RC2 or later.
3
What versions of Joomla! are affected by CVE-2007-4777?
CVE-2007-4777 affects Joomla! versions 1.5.0_beta, 1.5.0_beta2, and 1.5.0_rc1.
4
What type of attack does CVE-2007-4777 involve?
CVE-2007-4777 involves SQL injection attacks that can compromise database integrity.
5
Is CVE-2007-4777 related to any other vulnerabilities?
Yes, CVE-2007-4777 may be related to CVE-2007-4778.