First published: Mon Feb 02 2009(Updated: )
SQL injection vulnerability in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mpid parameter in a sign action to index.php, a different vector than CVE-2008-3132.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla com beamospetition | =1.0.12 | |
Joomla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0377 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2009-0377, update the beamospetition component to a version that is not affected, or apply any available security patches provided by Joomla.
CVE-2009-0377 affects version 1.0.12 of the beamospetition component for Joomla!
CVE-2009-0377 is vulnerable to SQL injection attacks which can lead to data breaches and unauthorized access.
Yes, if Joomla sites are still running the vulnerable version of the beamospetition component, they remain at risk from CVE-2009-0377.