CVE-2009-4628: SQL Injection
Published Jan 18, 2010
·Updated
SQL injection vulnerability in the TemplatePlaza.com TPDugg (comtpdugg) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tags action to index.php.
Affected Software
4 affected components
TemplatePlaza com TPDugg=1.1
Joomla Joomla\!
All of the following
TemplatePlaza com TPDugg=1.1
Joomla Joomla\!
Remediation
Event History
Jan 18, 2010
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
08:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·08:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Who can exploit this issue?
A remote attacker can exploit it over the network without authentication, provided the affected TPDugg component is reachable through Joomla!.
2
What input is vulnerable?
The vulnerable input is the id parameter when index.php is invoked with a tags action. Crafted values can be used to execute arbitrary SQL commands.
3
Is a fix available?
Yes. A patch is available for this issue.