CVE-2008-0918: SQL Injection
SQL injection vulnerability in includes/countdlorlink.inc.php in the astatsPRO (comastatspro) 1.0.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to getfile.php, a different vector than CVE-2008-0839. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0918?
CVE-2008-0918 has a high severity rating due to its potential for remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2008-0918?
To fix CVE-2008-0918, it is recommended to upgrade the astatsPRO component to a version that is not vulnerable or apply proper input validation and sanitization.
What are the affected products of CVE-2008-0918?
CVE-2008-0918 affects astatsPRO version 1.0.1 and Joomla! component com_astatspro version 1.0.1.
Can CVE-2008-0918 lead to data leakage?
Yes, CVE-2008-0918 can potentially lead to data leakage as attackers may gain unauthorized access to the database.
Is CVE-2008-0918 an injection vulnerability?
Yes, CVE-2008-0918 is classified as an SQL injection vulnerability, allowing attackers to manipulate database queries.