CVE-2009-4428: SQL Injection
SQL injection vulnerability in the JoomPortfolio (comjoomportfolio) component 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the secid parameter in a showcat action to index.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4428?
The severity of CVE-2009-4428 is critical due to its potential to allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2009-4428?
To fix CVE-2009-4428, you should upgrade the JoomPortfolio component to a patched version or implement input validation on the secid parameter.
What components are affected by CVE-2009-4428?
CVE-2009-4428 specifically affects the JoomPortfolio component version 1.0.0.
Can CVE-2009-4428 be exploited remotely?
Yes, CVE-2009-4428 can be exploited remotely by attackers through the index.php file.
Is CVE-2009-4428 a common vulnerability?
CVE-2009-4428 is known to be a significant SQL injection vulnerability that has been identified in Joomla! components.