CVE-2010-4902: SQL Injection
Published Oct 8, 2011
·Updated
Multiple SQL injection vulnerabilities in the Clantools (comclantools) component 1.2.3 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) squad or (2) showgame parameter to index.php.
Affected Software
2 affected components
Joomla-clantools Clantools=com_clantools-1.2.3
Joomla Joomla\!
Event History
Oct 8, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
10:55 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-4902?
CVE-2010-4902 is classified as a high severity vulnerability due to its potential for remote code execution via SQL injection.
2
How do I fix CVE-2010-4902?
To fix CVE-2010-4902, upgrade the Clantools component to a version that is not affected by this vulnerability.
3
What software is affected by CVE-2010-4902?
CVE-2010-4902 affects the Clantools component version 1.2.3 for Joomla!.
4
Can CVE-2010-4902 be exploited remotely?
Yes, CVE-2010-4902 can be exploited remotely by attackers to execute arbitrary SQL commands.
5
Are there any known exploits for CVE-2010-4902?
Yes, there are known exploits that demonstrate the SQL injection vulnerabilities present in CVE-2010-4902.