First published: Wed Oct 05 2011(Updated: )
SQL injection vulnerability in the JE Guestbook (com_jeguestbook) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the d_itemid parameter in an item_detail action to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
harmistechnology com jeguestbook | =1.0 | |
Joomla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4865 is classified as a medium severity vulnerability due to its potential for SQL injection attacks.
To fix CVE-2010-4865, upgrade the JE Guestbook component to the latest version provided by Harmis Technology.
CVE-2010-4865 specifically affects the JE Guestbook component version 1.0 for Joomla!.
CVE-2010-4865 allows remote attackers to execute arbitrary SQL commands through SQL injection.
No, Joomla! as a platform is not directly affected, but specific components like JE Guestbook are vulnerable.