CVE-2008-0689: SQL Injection

Published Feb 12, 2008
·
Updated

SQL injection vulnerability in index.php in the Marketplace (commarketplace) 1.1.1 and 1.1.1-pl1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a showcategory action.

Affected Software

2 affected components
Joomla Com Marketplace=1.1.1-pl1
Joomla Com Marketplace=1.1.1

Event History

Feb 12, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2008-0689?

CVE-2008-0689 has been classified as having a medium severity due to the risk of unauthorized SQL command execution.

2

How do I fix CVE-2008-0689?

To fix CVE-2008-0689, upgrade to the latest version of the Marketplace component for Joomla! that has addressed this vulnerability.

3

What impact does CVE-2008-0689 have on Joomla! sites?

CVE-2008-0689 allows remote attackers to manipulate the database by executing arbitrary SQL commands through a vulnerable parameter.

4

Which versions of the Marketplace component are affected by CVE-2008-0689?

CVE-2008-0689 affects versions 1.1.1 and 1.1.1-pl1 of the Marketplace component for Joomla!.

5

Can CVE-2008-0689 be exploited without authentication?

Yes, CVE-2008-0689 can be exploited by remote attackers without requiring authentication.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203