CVE-2008-0795: SQL Injection
Published Feb 15, 2008
·Updated
SQL injection vulnerability in index.php in the MGFi XfaQ (comxfaq) 1.2 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an answer action.
Affected Software
3 affected components
MGFi XfaQ=1.2
Joomla joomla=1.0
Mambo Mambo=4.5
Event History
Feb 15, 2008
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0795?
CVE-2008-0795 is categorized as a high severity SQL injection vulnerability.
2
How do I fix CVE-2008-0795?
To fix CVE-2008-0795, update the MGFi XfaQ component to a version that addresses this SQL injection issue.
3
What software is affected by CVE-2008-0795?
CVE-2008-0795 affects Mambo 4.5, Joomla! 1.0, and the MGFi XfaQ 1.2 component.
4
What type of vulnerability is CVE-2008-0795?
CVE-2008-0795 is an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
5
Can CVE-2008-0795 lead to data compromise?
Yes, CVE-2008-0795 can potentially allow attackers to manipulate or disclose sensitive data through unauthorized SQL commands.