First published: Tue Feb 12 2008(Updated: )
SQL injection vulnerability in index.php in the NeoReferences (com_neoreferences) 1.3.1 and 1.3.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla! | =1.3.1 | |
Mambo | =1.3.3 | |
Mambo | =1.3.1 | |
Joomla! | =1.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0686 is considered a critical SQL injection vulnerability that could allow attackers to execute arbitrary SQL commands.
To fix CVE-2008-0686, it is recommended to update the NeoReferences component to a version that is not vulnerable, such as versions later than 1.3.3.
CVE-2008-0686 affects Joomla! versions 1.3.1 and 1.3.3 of the NeoReferences component.
Yes, CVE-2008-0686 can be exploited by remote attackers due to the SQL injection vulnerability.
The catid parameter is exploited in CVE-2008-0686 to execute arbitrary SQL commands.