CVE-2008-4105: Input Validation
JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "variable injection" attacks and have unspecified other impact.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4105?
CVE-2008-4105 is classified as a moderate severity vulnerability that allows remote variable injection attacks in Joomla! 1.5 versions before 1.5.7.
How do I fix CVE-2008-4105?
To fix CVE-2008-4105, you should upgrade Joomla! to version 1.5.7 or later to ensure that variables are properly sanitized.
What versions of Joomla! are affected by CVE-2008-4105?
CVE-2008-4105 affects Joomla! versions 1.5.0 to 1.5.6 inclusive.
What type of attacks can be executed due to CVE-2008-4105?
CVE-2008-4105 allows attackers to conduct variable injection attacks, which may lead to unauthorized actions or data exposure.
Is CVE-2008-4105 a local or remote vulnerability?
CVE-2008-4105 is a remote vulnerability, which means it can be exploited by an attacker without physical access to the system.