CVE-2010-4944: SQL Injection
Published Oct 9, 2011
·Updated
SQL injection vulnerability in the Elite Experts (comeliteexperts) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showExpertProfileDetailed action to index.php.
Affected Software
3 affected components
Joomla Com Elite Experts
Joomla Joomla\!
Mambo-foundation Mambo
Event History
Oct 9, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
10:55 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-4944?
CVE-2010-4944 is considered a high severity vulnerability due to the potential for remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2010-4944?
To fix CVE-2010-4944, update the Elite Experts component to its latest version or apply vendor-provided patches.
3
Which applications are affected by CVE-2010-4944?
CVE-2010-4944 affects the Elite Experts component for Joomla and Mambo platforms.
4
What type of vulnerability is CVE-2010-4944?
CVE-2010-4944 is an SQL injection vulnerability that allows the execution of arbitrary SQL commands.
5
Can CVE-2010-4944 be exploited without authentication?
Yes, CVE-2010-4944 can be exploited by remote attackers without requiring authentication.