First published: Thu Feb 05 2009(Updated: )
SQL injection vulnerability in the Eventing (com_eventing) 1.6.x component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | =1.6 | |
Joomla | =1.6.1 | |
Joomla | =1.6.2 | |
Joomla | =1.6.3 | |
Joomla | =1.6.4 | |
Joomla | =1.6.5 | |
Joomla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0421 is classified as a high severity vulnerability due to its potential for remote SQL injection attacks.
To fix CVE-2009-0421, you should update the Eventing component to the latest version that is available for Joomla!
CVE-2009-0421 affects Joomla! Eventing component version 1.6.x, including versions 1.6 to 1.6.5.
CVE-2009-0421 is an SQL injection vulnerability, allowing attackers to execute arbitrary SQL commands.
Yes, CVE-2009-0421 can be exploited remotely without authentication, making it particularly dangerous.