CVE-2015-1477: SQL Injection
Published Feb 4, 2015
·Updated
SQL injection vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewad task to classifieds/offerring-ads.
Affected Software
1 affected component
CMSJunkie J-classifiedsmanager Joomla\!
Event History
Feb 4, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1477?
CVE-2015-1477 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2015-1477?
To fix CVE-2015-1477, update the CMSJunkie J-ClassifiedsManager component to the latest version that addresses this vulnerability.
3
What type of attack does CVE-2015-1477 allow?
CVE-2015-1477 allows remote attackers to execute arbitrary SQL commands.
4
Which software is affected by CVE-2015-1477?
CVE-2015-1477 affects the CMSJunkie J-ClassifiedsManager component for Joomla!.
5
What parameter is exploited in CVE-2015-1477?
The vulnerability is exploited via the 'id' parameter in a viewad task to classifieds/offerring-ads.