First published: Sat Jun 27 2009(Updated: )
SQL injection vulnerability in the (1) casinobase (com_casinobase), (2) casino_blackjack (com_casino_blackjack), and (3) casino_videopoker (com_casino_videopoker) components 0.3.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | ||
Joomla com casiino blackjack | =0.3.1 | |
Joomla | =0.3.1 | |
Joomla | =0.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2239 is classified as a high severity SQL injection vulnerability.
To fix CVE-2009-2239, upgrade the affected components to their latest versions or implement input validation to sanitize the Itemid parameter.
CVE-2009-2239 affects the components casinobase, casino_blackjack, and casino_videopoker version 0.3.1.
Yes, CVE-2009-2239 allows remote attackers to execute arbitrary SQL commands, which could lead to remote code execution under certain circumstances.
CVE-2009-2239 is specific to version 0.3.1 of the affected Joomla! components and may be present in earlier versions.