First published: Mon Mar 24 2008(Updated: )
SQL injection vulnerability in the Alberghi (com_alberghi) 2.1.3 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | ||
Mambo | ||
joomlaitalia com Alberghi | =2.1.3 | |
mamboitalia com Alberghi | =2.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1459 is considered to have a high severity due to its potential for SQL injection, allowing remote attackers to execute arbitrary SQL commands.
To fix CVE-2008-1459, upgrade the Alberghi component to version 2.1.4 or later, which addresses this vulnerability.
CVE-2008-1459 affects the Alberghi component version 2.1.3 and earlier for both Mambo and Joomla! platforms.
Yes, CVE-2008-1459 can be exploited remotely, allowing attackers to perform SQL injection attacks from outside the target system.
CVE-2008-1459 is a concern for website security because it allows attackers to manipulate the database, potentially leading to data theft or unauthorized administrative access.