CVE-2009-2014: SQL Injection
Published Jun 9, 2009
·Updated
SQL injection vulnerability in the ComSchool (comschool) component 1.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the classid parameter in a showclass action to index.php.
Affected Software
2 affected components
Joomla joomla
Joomla Com School=1.4
Event History
Jun 9, 2009
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
07:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-2014?
CVE-2009-2014 is considered a high-severity SQL injection vulnerability.
2
How do I fix CVE-2009-2014?
To fix CVE-2009-2014, update the ComSchool component to a version that is not affected by this vulnerability.
3
What types of attacks can be executed via CVE-2009-2014?
CVE-2009-2014 allows attackers to execute arbitrary SQL commands by exploiting the SQL injection flaw.
4
Which version of ComSchool is vulnerable to CVE-2009-2014?
ComSchool version 1.4 is vulnerable to CVE-2009-2014.
5
Is Joomla! itself affected by CVE-2009-2014?
No, Joomla! itself is not affected; only the ComSchool component version 1.4 has this vulnerability.