PT-2007-5918 · Open Source Matters · Joomla!

Publicado

2007-09-10

·

Atualizado

2017-07-29

·

CVE-2007-4778

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Joomla! versions 1.5 Beta1 through 1.5 RC1
Description: The issue allows remote attackers to execute arbitrary SQL commands via the filter parameter in an archive action to specific PHP files, including "archive.php", "category.php", or "section.php" in the models/ directory.
Recommendations: For Joomla! versions 1.5 Beta1 through 1.5 RC1, consider restricting access to the archive action in the content component until a fix is available. As a temporary workaround, avoid using the filter parameter in the affected PHP files.

Correção

RCE

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-4778

Produtos afetados

Joomla!