First published: Fri Jun 27 2008(Updated: )
SQL injection vulnerability in the EXP Shop (com_expshop) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show_payment action to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Feellove Exp Shop Component | =1.0 | |
Joomla! Com Expshop |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2892 is classified as a high severity vulnerability due to its potential for remote exploitation of SQL injection flaws.
To fix CVE-2008-2892, you should upgrade to a newer version of the EXP Shop component that addresses this SQL injection vulnerability.
CVE-2008-2892 affects Joomla! sites that have the EXP Shop component version 1.0 installed.
CVE-2008-2892 allows remote attackers to execute arbitrary SQL commands, potentially leading to data manipulation or unauthorized access.
If upgrading the EXP Shop component is not immediately possible, consider disabling the component until a patch is available.