First published: Mon Jul 27 2009(Updated: )
SQL injection vulnerability in the Joomlaequipment (aka JUser or com_juser) component 2.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a show_profile action to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomlaequipment JUser | =2.0.4 | |
Joomla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2601 is considered a critical vulnerability due to its ability to allow remote attackers to execute arbitrary SQL commands.
Fixing CVE-2009-2601 involves upgrading the Joomlaequipment JUser component to a version that is not vulnerable.
CVE-2009-2601 specifically affects Joomlaequipment JUser component version 2.0.4.
Yes, exploitation of CVE-2009-2601 can lead to data loss or corruption due to unauthorized SQL command execution.
Yes, using an outdated version of Joomla that includes the vulnerable 2.0.4 JUser component leaves your site open to CVE-2009-2601.