CVE-2008-0799: SQL Injection
Published Feb 15, 2008
·Updated
SQL injection vulnerability in index.php in the Quiz (comquiz) 0.81 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a usertstshw action.
Affected Software
2 affected components
Joomla Com Quiz<=0.81
Mambo Com Quiz<=0.81
Event History
Feb 15, 2008
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0799?
CVE-2008-0799 has a high severity rating due to its potential for remote SQL command execution.
2
How do I fix CVE-2008-0799?
To fix CVE-2008-0799, upgrade your Mambo or Joomla! installation to a version later than 0.81.
3
What software is affected by CVE-2008-0799?
CVE-2008-0799 affects the Quiz component (com_quiz) versions 0.81 and earlier for both Mambo and Joomla! platforms.
4
Can CVE-2008-0799 be exploited remotely?
Yes, CVE-2008-0799 can be exploited remotely through the tid parameter in a user_tst_shw action.
5
What type of vulnerability is CVE-2008-0799?
CVE-2008-0799 is classified as an SQL injection vulnerability.