CVE-2008-2093: SQL Injection
Published May 6, 2008
·Updated
SQL injection vulnerability in the Profiler (comcomprofiler) component in Community Builder for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a userProfile action to index.php.
Affected Software
3 affected components
Joomla Com Comprofiler
Joomlapolis Community Builder
Mambo Com Comprofiler
Event History
May 6, 2008
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2093?
CVE-2008-2093 is classified as a medium-severity SQL injection vulnerability.
2
How do I fix CVE-2008-2093?
To fix CVE-2008-2093, update to the latest version of Community Builder or apply available security patches.
3
What systems are affected by CVE-2008-2093?
CVE-2008-2093 affects Community Builder in Joomla and Mambo platforms.
4
Can CVE-2008-2093 be exploited remotely?
Yes, CVE-2008-2093 can be exploited remotely by attackers to execute arbitrary SQL commands.
5
What component is responsible for CVE-2008-2093?
CVE-2008-2093 is related to the Profiler component in Community Builder.