CVE-2009-0494: SQL Injection
SQL injection vulnerability in the Portfol (comportfol) 1.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the vcatid parameter in a viewcategory action to index.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0494?
CVE-2009-0494 is considered a critical vulnerability due to its potential for remote exploitation and arbitrary SQL command execution.
How do I fix CVE-2009-0494?
To fix CVE-2009-0494, upgrade the Portfol component to its latest version, ensuring all SQL queries are properly sanitized.
What software is affected by CVE-2009-0494?
CVE-2009-0494 specifically affects the com_portfol version 1.2 component for Joomla!.
Can CVE-2009-0494 be exploited remotely?
Yes, CVE-2009-0494 can be exploited remotely by attackers through the vcatid parameter in a viewcategory action to index.php.
What impact does CVE-2009-0494 have on a vulnerable system?
CVE-2009-0494 allows attackers to execute arbitrary SQL commands, potentially leading to data exfiltration, modification, or system compromise.