CVE-2008-0557: SQL Injection
Published Feb 4, 2008
·Updated
SQL injection vulnerability in index.php in the CatalogShop (comcatalogshop) 1.0b1 componenent for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
Affected Software
1 affected component
Mamboserver Catalogshop=1.0b1
Event History
Feb 4, 2008
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0557?
CVE-2008-0557 is classified as a critical-severity SQL injection vulnerability.
2
How do I fix CVE-2008-0557?
To fix CVE-2008-0557, you should update the CatalogShop component to a version that does not contain this vulnerability.
3
What systems are affected by CVE-2008-0557?
CVE-2008-0557 affects the CatalogShop 1.0b1 component for Mambo and Joomla! installations.
4
Can CVE-2008-0557 allow attackers to manipulate data?
Yes, CVE-2008-0557 allows remote attackers to execute arbitrary SQL commands, potentially leading to data manipulation.
5
Is there a known exploit for CVE-2008-0557?
Yes, there are known exploits that take advantage of the SQL injection vulnerability in CVE-2008-0557.