PT-2007-1858 · Open Source Matters · Joomla!

Published

2007-01-19

·

Updated

2018-10-16

·

CVE-2007-0387

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Joomla! Weblinks component version prior to SVN 20070118
Description: A SQL injection issue exists, allowing remote attackers to execute arbitrary SQL commands. This is achieved by manipulating the catid parameter in the models/category.php file of the Weblinks component.
Recommendations: For Joomla! Weblinks component version prior to SVN 20070118, avoid using the catid parameter in the affected models/category.php file until the issue is resolved. As a temporary workaround, consider restricting access to the Weblinks component to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0387

Affected Products

Joomla!