First published: Mon Mar 08 2010(Updated: )
SQL injection vulnerability in the Keep It Simple Stupid (KISS) Software Advertiser (com_ksadvertiser) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a showcats action to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kiss Software KSAdvertiser | ||
Joomla | ||
All of | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0946 is considered a medium severity SQL injection vulnerability.
To fix CVE-2010-0946, update the KISS Software Advertiser component to the latest version that addresses this SQL injection issue.
CVE-2010-0946 affects the KISS Software Advertiser component for Joomla! installations.
CVE-2010-0946 enables remote attackers to execute arbitrary SQL commands through a vulnerable parameter.
Yes, there are documented exploits that demonstrate the SQL injection vulnerability in CVE-2010-0946.