CVE-2009-4199: SQL Injection
Multiple SQL injection vulnerabilities in the Mambo Resident (aka Mos Res or commosres) component 1.0f for Mambo and Joomla!, when magicquotesgpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) propertyuid parameter in a viewproperty action to index.php and the (2) regID parameter in a showregion action to index.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4199?
CVE-2009-4199 is classified as a medium-severity vulnerability due to its potential to allow SQL injection attacks.
How do I fix CVE-2009-4199?
To mitigate CVE-2009-4199, you should enable magic_quotes_gpc or, preferably, upgrade to a patched version of the Mambo Resident component.
What components are affected by CVE-2009-4199?
CVE-2009-4199 affects the Mambo Resident component version 1.0f when used with Mambo or Joomla! installations.
Can CVE-2009-4199 be exploited remotely?
Yes, CVE-2009-4199 allows remote attackers to execute arbitrary SQL commands, making it easily exploitable.
What specific parameters are vulnerable in CVE-2009-4199?
The property_uid parameter in a viewproperty action to index.php is specifically vulnerable in CVE-2009-4199.