Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Spk

Researcher fromDarkMatter Crew
#35460of 53,622
7.5Total CVSS
Vulnerabilities · 1
PT-2009-1951
7.5
2009-03-17
Mambo Foundation · Mambo · CVE-2008-6481
**Name of the Vulnerable Software and Affected Versions** Joomla! version 1.0.2 Mambo version 1.0.2 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved by exploiting the `id` parameter in an edit task to "index.php". **Recommendations** For Joomla! version 1.0.2, avoid using the `id` parameter in the affected API endpoint until the issue is resolved. For Mambo version 1.0.2, restrict access to the vulnerable component to minimize the risk of exploitation.