First published: Fri Feb 15 2008(Updated: )
SQL injection vulnerability in index.php in the PAXXGallery (com_paxxgallery) 0.2 component for Mambo and Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the iid parameter in a view action, and possibly (2) the userid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PAXXGallery com PAXXGallery | =0.2 | |
Joomla | ||
Mambo |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0801 has a medium severity rating due to its potential for remote SQL injection exploits.
To fix CVE-2008-0801, it is recommended to upgrade the PAXXGallery component to a patched version or implement input validation to sanitize the iid and userid parameters.
CVE-2008-0801 affects the PAXXGallery component version 0.2 used with Mambo and Joomla! installations.
Yes, CVE-2008-0801 allows remote attackers to execute arbitrary SQL commands, making it a serious remote exploitation risk.
Exploiting CVE-2008-0801 can lead to unauthorized data access, data modification, and possibly full control over the affected database.