CVE-2008-0514: SQL Injection
Published Jan 31, 2008
·Updated
SQL injection vulnerability in index.php in the Glossary (comglossary) 2.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a display action.
Affected Software
2 affected components
Joomla Glossary=2.0
Mambo Glossary=2.0
Event History
Jan 31, 2008
CVE Published
via MITRE·07:30 PM
Data Sourced
via MITRE·07:30 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0514?
CVE-2008-0514 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2008-0514?
To fix CVE-2008-0514, update to the latest version of the Glossary component for Mambo or Joomla.
3
What software is affected by CVE-2008-0514?
CVE-2008-0514 affects the Glossary component version 2.0 for both Mambo and Joomla.
4
What type of vulnerability is CVE-2008-0514?
CVE-2008-0514 is an SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
5
What parameters can be exploited in CVE-2008-0514?
The catid parameter in the display action of index.php can be exploited in CVE-2008-0514.