CVE-2008-0817: SQL Injection
Published Feb 19, 2008
·Updated
SQL injection vulnerability in the comfilebase component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in a selectfolder action.
Affected Software
2 affected components
Joomla Com Filebase Component
Mambo Com Filebase Component
Event History
Feb 19, 2008
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0817?
CVE-2008-0817 has a medium severity rating due to its potential for SQL injection attacks.
2
How do I fix CVE-2008-0817?
To fix CVE-2008-0817, you should update the com_filebase component to the latest version provided by Joomla! or Mambo.
3
What platforms are affected by CVE-2008-0817?
CVE-2008-0817 affects Joomla! and Mambo installations that utilize the com_filebase component.
4
What type of attack does CVE-2008-0817 facilitate?
CVE-2008-0817 facilitates SQL injection attacks, allowing attackers to execute arbitrary SQL commands.
5
Can CVE-2008-0817 be exploited remotely?
Yes, CVE-2008-0817 can be exploited remotely if the vulnerable component is exposed to the internet.