CVE-2009-2638: SQL Injection
Published Jul 28, 2009
·Updated
SQL injection vulnerability in the AkoBook (comakobook) component 2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a reply action to index.php.
Affected Software
2 affected components
Joomla joomla
Konze Com Akobook=2.3
Event History
Jul 28, 2009
CVE Published
via MITRE·07:06 PM
Data Sourced
via MITRE·07:06 PM
Description
Data Sourced
07:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-2638?
CVE-2009-2638 is classified as a medium severity SQL injection vulnerability.
2
How do I fix CVE-2009-2638?
To fix CVE-2009-2638, update the AkoBook component to the latest version provided by the vendor.
3
Who is affected by CVE-2009-2638?
Users of Joomla! with the AkoBook component version 2.3 are affected by CVE-2009-2638.
4
What type of vulnerability is CVE-2009-2638?
CVE-2009-2638 is an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
5
What is the gbid parameter in CVE-2009-2638?
The gbid parameter in CVE-2009-2638 is a variable in the reply action of the AkoBook component that is exploited for SQL injection.