CVE-2010-1522: SQL Injection
Multiple SQL injection vulnerabilities in the BookLibrary Basic (combooklibrary) component 1.5.3 before 1.5.320100620 for Joomla! allow remote attackers to execute arbitrary SQL commands via the bid[] parameter in a (1) lendrequest or (2) savelendrequest action to index.php, the id parameter in a (3) mdownload or (4) downitsf action to index.php, or (5) the searchtext parameter in a search action to index.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1522?
CVE-2010-1522 is considered a high severity vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2010-1522?
To fix CVE-2010-1522, upgrade the BookLibrary Basic component to version 1.5.3_2010_06_20 or later.
What are the potential impacts of exploiting CVE-2010-1522?
Exploiting CVE-2010-1522 can allow attackers to execute arbitrary SQL commands on the affected Joomla! site.
Which versions of BookLibrary Basic are affected by CVE-2010-1522?
CVE-2010-1522 affects BookLibrary Basic component version 1.5.3 prior to 1.5.3_2010_06_20.
Is Joomla! itself vulnerable due to CVE-2010-1522?
No, Joomla! itself is not vulnerable; only the BookLibrary Basic component is affected by CVE-2010-1522.