First published: Thu Jul 09 2009(Updated: )
SQL injection vulnerability in the K2 (com_k2) component 1.0.1 Beta and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter in an itemlist action to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomlaworks K2 | <=1.0.1 | |
Joomla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2395 has a high severity level due to its potential to allow remote SQL command execution.
You can fix CVE-2009-2395 by upgrading the K2 component to a version later than 1.0.1 Beta.
CVE-2009-2395 affects K2 component versions 1.0.1 Beta and earlier used in Joomla! systems.
While CVE-2009-2395 may have been exploited in the past, its current status should be verified through recent threat assessments.
CVE-2009-2395 can lead to unauthorized access to databases and manipulation of sensitive data.