First published: Sat Oct 08 2011(Updated: )
Multiple SQL injection vulnerabilities in the Clantools (com_clantools) component 1.2.3 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) squad or (2) showgame parameter to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Clantools | =com_clantools-1.2.3 | |
Joomla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4902 is classified as a high severity vulnerability due to its potential for remote code execution via SQL injection.
To fix CVE-2010-4902, upgrade the Clantools component to a version that is not affected by this vulnerability.
CVE-2010-4902 affects the Clantools component version 1.2.3 for Joomla!.
Yes, CVE-2010-4902 can be exploited remotely by attackers to execute arbitrary SQL commands.
Yes, there are known exploits that demonstrate the SQL injection vulnerabilities present in CVE-2010-4902.