CVE-2009-4474: SQL Injection
SQL injection vulnerability in the Mike de Boer zoom (comzoom) component 2.0 for Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4474?
CVE-2009-4474 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2009-4474?
To fix CVE-2009-4474, it is recommended to upgrade the com_zoom component to a version that patches this SQL injection vulnerability.
What systems are affected by CVE-2009-4474?
CVE-2009-4474 affects version 2.0 of the com_zoom component for Mambo.
Can CVE-2009-4474 be exploited remotely?
Yes, CVE-2009-4474 can be exploited remotely through specially crafted requests to the vulnerable index.php script.
What type of vulnerability is CVE-2009-4474?
CVE-2009-4474 is an SQL injection vulnerability that allows attackers to manipulate SQL queries executed by the application.