First published: Wed Apr 21 2010(Updated: )
SQL injection vulnerability in the Quick News (com_quicknews) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a view_item action to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | ||
quicknews |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4785 has a high severity rating due to its SQL injection capabilities, allowing remote attackers to execute arbitrary SQL commands.
To fix CVE-2009-4785, update the Quick News component for Joomla! to the latest version that addresses this SQL injection vulnerability.
CVE-2009-4785 affects Joomla! installations using the Quick News component, specifically the version developed by Bhavesh Chauhan.
Yes, CVE-2009-4785 can potentially lead to data loss as it allows attackers to execute arbitrary SQL commands which may manipulate or delete data.
To protect your Joomla! installation from CVE-2009-4785, ensure you are running the latest version of the Quick News component and regularly apply security updates.