CVE-2010-4904: SQL Injection
SQL injection vulnerability in the Aardvertiser (comaardvertiser) component 2.1 and 2.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catname parameter in a view action to index.php. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4904?
CVE-2010-4904 has a moderate severity level due to its potential for remote SQL injection attacks.
How do I fix CVE-2010-4904?
To mitigate CVE-2010-4904, update the Aardvertiser component to version 2.1.2 or later.
What software is affected by CVE-2010-4904?
CVE-2010-4904 affects the Aardvertiser component versions 2.1 and 2.1.1 for Joomla!.
What type of vulnerability is CVE-2010-4904?
CVE-2010-4904 is an SQL injection vulnerability that allows execution of arbitrary SQL commands.
Who can exploit CVE-2010-4904?
Remote attackers can exploit CVE-2010-4904 by sending specially crafted requests to the application.