First published: Mon Feb 23 2009(Updated: )
SQL injection vulnerability in the Simple Review (com_simple_review) component 1.3.5 for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the category parameter to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Simple Review | =1.3.5 | |
Joomla | ||
Mambo |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0706 has a high severity rating due to its potential for remote SQL injection attacks.
To fix CVE-2009-0706, upgrade to a patched version of the Simple Review component that addresses the SQL injection vulnerability.
CVE-2009-0706 specifically affects version 1.3.5 of the Simple Review component for Joomla! and Mambo.
CVE-2009-0706 is classified as an SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
CVE-2009-0706 can be exploited by remote attackers who manipulate the category parameter in index.php.