CVE-2008-6148: SQL Injection
Published Feb 16, 2009
·Updated
SQL injection vulnerability in the Live Ticker (comliveticker) module 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a viewticker action to index.php.
Affected Software
4 affected components
Raven-worx Liveticker=1.0
Joomla joomla
All of the following
Raven-worx Liveticker=1.0
Joomla joomla
Event History
Feb 16, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
05:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·05:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-6148?
The severity of CVE-2008-6148 is rated high with a score of 7.5.
2
How does CVE-2008-6148 impact Joomla! websites?
CVE-2008-6148 allows remote attackers to exploit SQL injection vulnerabilities, which can lead to unauthorized data access or manipulation.
3
What is the risk associated with CVE-2008-6148?
The risk associated with CVE-2008-6148 is classified as 52, indicating a significant level of concern.
4
How do I fix CVE-2008-6148?
To fix CVE-2008-6148, update the Live Ticker module to the latest version that addresses the SQL injection vulnerability.
5
What systems are affected by CVE-2008-6148?
CVE-2008-6148 specifically affects Joomla! websites using the Live Ticker (com_liveticker) module version 1.0.