First published: Fri Feb 22 2008(Updated: )
SQL injection vulnerability in includes/count_dl_or_link.inc.php in the astatsPRO (com_astatspro) 1.0.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to getfile.php, a different vector than CVE-2008-0839. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla! Com Astatspro | =1.0.1 | |
Joomla! Com Astatspro | =1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0918 has a high severity rating due to its potential for remote attackers to execute arbitrary SQL commands.
To fix CVE-2008-0918, it is recommended to upgrade the astatsPRO component to a version that is not vulnerable or apply proper input validation and sanitization.
CVE-2008-0918 affects astatsPRO version 1.0.1 and Joomla! component com_astatspro version 1.0.1.
Yes, CVE-2008-0918 can potentially lead to data leakage as attackers may gain unauthorized access to the database.
Yes, CVE-2008-0918 is classified as an SQL injection vulnerability, allowing attackers to manipulate database queries.