First published: Tue Apr 27 2010(Updated: )
SQL injection vulnerability in the SermonSpeaker (com_sermonspeaker) component before 3.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a speakerpopup action to index.php. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Martin Hess Com SermonSpeaker | =3.2.1 | |
Joomla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1559 is considered to be a high-severity SQL injection vulnerability that can allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2010-1559, you should upgrade the SermonSpeaker component to version 3.2.1 or later.
CVE-2010-1559 affects the SermonSpeaker component before version 3.2.1 when used with Joomla!.
Yes, CVE-2010-1559 can be exploited remotely via the id parameter in a speakerpopup action to index.php.
If your site is vulnerable to CVE-2010-1559, it is recommended to immediately update the SermonSpeaker component to a patched version to mitigate the risk.