CVE-2009-4619: SQL Injection
SQL injection vulnerability in the Lucy Games (comlucygames) component 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gameid parameter in a game action to index.php. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The vulnerability is remotely exploitable with no authentication required. An attacker can send a request to Joomla!'s index.php using the Lucy Games component's game action and a crafted gameid parameter.
Which installations are affected?
The affected software identified is the Lucy Games (com_lucygames) component version 1.5.4 for Joomla!. The provided information does not establish whether other component versions are affected.
What is the potential impact of successful exploitation?
Successful exploitation allows execution of arbitrary SQL commands. The reported impact includes compromise of confidentiality, integrity, and availability.