First published: Wed Mar 12 2008(Updated: )
SQL injection vulnerability in index.php in the eWriting (com_ewriting) 1.2.1 module for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a selectcat action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ewriting Ewriting | =1.2.1 | |
Joomla Com Ewriting | =1.2.1 | |
Mambo Com Ewriting | =1.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1297 is rated as a high severity vulnerability due to its potential for remote SQL command execution.
To fix CVE-2008-1297, update to a patched version of the eWriting module or implement input validation to sanitize user inputs.
CVE-2008-1297 affects the eWriting module version 1.2.1 for both Mambo and Joomla! CMS.
Yes, CVE-2008-1297 can allow remote attackers to execute arbitrary SQL commands, potentially leading to unauthorized data access.
While CVE-2008-1297 was identified in 2008, it remains a concern for any systems still running the vulnerable version of the eWriting module.