CVE-2009-2395: SQL Injection
Published Jul 9, 2009
·Updated
SQL injection vulnerability in the K2 (comk2) component 1.0.1 Beta and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter in an itemlist action to index.php.
Affected Software
2 affected components
JoomlaWorks Com K2<=1.0.1
Joomla Joomla\!
Event History
Jul 9, 2009
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
04:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-2395?
CVE-2009-2395 has a high severity level due to its potential to allow remote SQL command execution.
2
How do I fix CVE-2009-2395?
You can fix CVE-2009-2395 by upgrading the K2 component to a version later than 1.0.1 Beta.
3
What systems are affected by CVE-2009-2395?
CVE-2009-2395 affects K2 component versions 1.0.1 Beta and earlier used in Joomla! systems.
4
Is CVE-2009-2395 being actively exploited?
While CVE-2009-2395 may have been exploited in the past, its current status should be verified through recent threat assessments.
5
What are the possible consequences of CVE-2009-2395?
CVE-2009-2395 can lead to unauthorized access to databases and manipulation of sensitive data.