First published: Wed Feb 13 2008(Updated: )
SQL injection vulnerability in Phil Taylor Comments (com_comments, aka Review Script) 0.5.8.5g and earlier component for Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Com Comments | <=0.5.8.5g | |
Phil Taylor Review Script | <=0.5.8.5g | |
Mambo Com Comments | <=0.5.8.5g | |
Phil Taylor Comments | <=0.5.8.5g |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0773 is considered a high severity vulnerability due to the potential for remote attackers to execute arbitrary SQL commands.
To mitigate CVE-2008-0773, upgrade to a patched version of the affected software beyond version 0.5.8.5g.
CVE-2008-0773 affects Mambo, Joomla, and Phil Taylor Comments components that are version 0.5.8.5g and earlier.
Yes, CVE-2008-0773 can lead to data compromise as it allows attackers to manipulate and extract sensitive data from the database.
Yes, CVE-2008-0773 is a SQL injection vulnerability that exploits the id parameter to execute arbitrary SQL commands.