First published: Wed Feb 20 2008(Updated: )
SQL injection vulnerability in index.php in the com_profile component for Joomla! allows remote attackers to execute arbitrary SQL commands via the oid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Com Profile | ||
Mambo Com Profile |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0846 has a severity rating that indicates a high risk due to the potential for arbitrary SQL command execution.
To mitigate CVE-2008-0846, update the com_profile component in your Joomla or Mambo installation to the latest version that addresses the SQL injection vulnerability.
CVE-2008-0846 affects Joomla and Mambo installations using the com_profile component.
Yes, CVE-2008-0846 can be exploited remotely by attackers through the oid parameter in index.php.
CVE-2008-0846 allows attackers to execute arbitrary SQL commands, which can lead to data compromise or unauthorized access.