PT-2007-5918 · Open Source Matters · Joomla!

Published

2007-09-10

·

Updated

2017-07-29

·

CVE-2007-4778

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Joomla! versions 1.5 Beta1 through 1.5 RC1
Description: The issue allows remote attackers to execute arbitrary SQL commands via the filter parameter in an archive action to specific PHP files, including "archive.php", "category.php", or "section.php" in the models/ directory.
Recommendations: For Joomla! versions 1.5 Beta1 through 1.5 RC1, consider restricting access to the archive action in the content component until a fix is available. As a temporary workaround, avoid using the filter parameter in the affected PHP files.

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-4778

Affected Products

Joomla!