CVE-2009-3964: SQL Injection
Published Nov 18, 2009
·Updated
SQL injection vulnerability in the NinjaMonials (comninjacentral) component 1.1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the testimID parameter in a display action to index.php.
Affected Software
2 affected components
Joomla Joomla\!
Ninjaforge Com Ninjamonials=1.1.0
Event History
Nov 18, 2009
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
11:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-3964?
CVE-2009-3964 has a moderate severity level due to its ability to execute arbitrary SQL commands.
2
How do I fix CVE-2009-3964?
To fix CVE-2009-3964, upgrade the NinjaMonials component to a version later than 1.1.0.
3
What types of systems are affected by CVE-2009-3964?
CVE-2009-3964 affects Joomla! systems using the NinjaMonials component version 1.1.0.
4
Can CVE-2009-3964 be exploited remotely?
Yes, CVE-2009-3964 can be exploited remotely by attackers through the 'testimID' parameter.
5
Is CVE-2009-3964 fixed in newer versions of NinjaMonials?
Yes, the vulnerability is fixed in versions of NinjaMonials released after 1.1.0.