CVE-2008-0800: SQL Injection
Published Feb 15, 2008
·Updated
SQL injection vulnerability in index.php in the McQuiz (commcquiz) 0.9 Final component for Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a usertstshw action.
Affected Software
1 affected component
Joomla Com Mcquiz=0.9
Event History
Feb 15, 2008
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0800?
CVE-2008-0800 has a severity rating of medium due to its SQL injection vulnerability.
2
How do I fix CVE-2008-0800?
To fix CVE-2008-0800, you should update the McQuiz component to a version beyond 0.9 that addresses the SQL injection issue.
3
What kind of attacks can CVE-2008-0800 enable?
CVE-2008-0800 can enable attackers to execute arbitrary SQL commands on the affected Joomla! site.
4
Which Joomla! component is affected by CVE-2008-0800?
CVE-2008-0800 affects the McQuiz (com_mcquiz) component version 0.9 Final for Joomla!.
5
Is CVE-2008-0800 still a current threat?
While CVE-2008-0800 is an older vulnerability, systems that have not been patched may still be at risk.