CVE-2009-4583: SQL Injection
Published Jan 6, 2010
·Updated
SQL injection vulnerability in the DhForum (comdhforum) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a grouplist action to index.php.
Affected Software
2 affected components
Joomla Com Dhforum
Joomla Joomla\!
Event History
Jan 6, 2010
CVE Published
via MITRE·09:33 PM
Data Sourced
via MITRE·09:33 PM
Description
Data Sourced
10:00 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-4583?
The severity of CVE-2009-4583 is considered medium due to its potential for SQL injection attacks.
2
How do I fix CVE-2009-4583?
To fix CVE-2009-4583, update the DhForum component to the latest version that addresses this SQL injection vulnerability.
3
What systems are affected by CVE-2009-4583?
CVE-2009-4583 affects Joomla! installations using the DhForum (com_dhforum) component.
4
What exploitation methods are possible with CVE-2009-4583?
Attackers can exploit CVE-2009-4583 by injecting arbitrary SQL commands through the 'id' parameter in a grouplist action.
5
Is CVE-2009-4583 still a threat today?
While CVE-2009-4583 has been resolved in later versions, any Joomla! installations running outdated versions remain at risk.