First published: Mon Apr 12 2010(Updated: )
SQL injection vulnerability in the JP Jobs (com_jp_jobs) component 1.4.1 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomlaprojects JP Jobs | <=1.4.1 | |
Joomlaprojects JP Jobs | =1.3.0 | |
Joomlaprojects JP Jobs | =1.3.1 | |
Joomla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1350 has a medium severity score due to its potential for SQL injection, allowing attackers to execute arbitrary SQL commands.
To fix CVE-2010-1350, update the JP Jobs component to version 1.4.2 or later, where the vulnerability has been addressed.
CVE-2010-1350 affects JP Jobs component versions 1.4.1 and earlier including 1.3.0 and 1.3.1.
Yes, CVE-2010-1350 can lead to data loss as it allows attackers to execute arbitrary SQL commands that may compromise database integrity.
Users of the Joomla! platform with the JP Jobs component installed are primarily affected by CVE-2010-1350.