CVE-2009-4625: SQL Injection
SQL injection vulnerability in the updateOnePage function in components/combfsurveypro/controller.php in BF Survey Pro Free (combfsurveyprofree) 1.2.4, and other versions before 1.2.6, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the table parameter in an updateOnePage action to index.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4625?
CVE-2009-4625 is classified as a High severity vulnerability due to the potential for remote code execution through SQL injection.
How do I fix CVE-2009-4625?
To fix CVE-2009-4625, update the BF Survey Pro Free component to version 1.2.6 or later.
What systems are impacted by CVE-2009-4625?
CVE-2009-4625 specifically affects BF Survey Pro Free versions 1.2.4 and below used on Joomla! sites.
How can attackers exploit CVE-2009-4625?
Attackers can exploit CVE-2009-4625 by sending crafted requests containing malicious SQL commands via the 'table' parameter in the updateOnePage function.
Is CVE-2009-4625 related to other vulnerabilities?
Yes, CVE-2009-4625 is a specific SQL injection vulnerability that is part of a broader category of injection flaws frequently found in web applications.