CVE-2014-0794: XSS
Published Jan 26, 2014
·Updated
SQL injection vulnerability in the JV Comment (comjvcomment) component before 3.0.3 for Joomla! allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a comment.like action to index.php.
Affected Software
4 affected components
Joomla Com Jvcomment=3.0.2
Joomla Joomla\!
All of the following
Joomla Com Jvcomment=3.0.2
Joomla Joomla\!
Event History
Jan 26, 2014
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-0794?
CVE-2014-0794 is classified as a high severity vulnerability due to its potential to allow remote authenticated users to execute arbitrary SQL commands.
2
How do I fix CVE-2014-0794?
To fix CVE-2014-0794, upgrade the JV Comment component to version 3.0.3 or later.
3
Who is affected by CVE-2014-0794?
CVE-2014-0794 affects Joomla! installations using the JV Comment component prior to version 3.0.3.
4
What type of vulnerability is CVE-2014-0794?
CVE-2014-0794 is an SQL injection vulnerability that can be exploited through the id parameter.
5
Can CVE-2014-0794 be exploited by unauthenticated users?
No, CVE-2014-0794 requires the attacker to be an authenticated user to exploit the SQL injection.