CVE-2008-2676: SQL Injection
Published Jun 12, 2008
·Updated
SQL injection vulnerability in the iJoomla News Portal (comnewsportal) component 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.
Affected Software
2 affected components
Joomla Com News Portal<=1.0
Joomla joomla
Event History
Jun 12, 2008
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2676?
CVE-2008-2676 is classified as a critical vulnerability due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2008-2676?
To fix CVE-2008-2676, upgrade to a version of the iJoomla News Portal component that is later than 1.0.
3
What types of attacks can be executed through CVE-2008-2676?
Through CVE-2008-2676, attackers may execute arbitrary SQL commands, potentially compromising the database.
4
Which Joomla! versions are affected by CVE-2008-2676?
CVE-2008-2676 affects Joomla! installations using the iJoomla News Portal component version 1.0 and earlier.
5
Is CVE-2008-2676 a local or remote vulnerability?
CVE-2008-2676 is a remote vulnerability that allows attackers to exploit it over the network.