Vulnerabilities > CVE-2007-0373 - SQL Injection vulnerability in Joomla 1.5.0Beta

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
joomla

Summary

Multiple SQL injection vulnerabilities in Joomla! 1.5.0 Beta allow remote attackers to execute arbitrary SQL commands via (1) the searchword parameter in certain files; the where parameter in (2) plugins/search/content.php or (3) plugins/search/weblinks.php; the text parameter in (4) plugins/search/contacts.php, (5) plugins/search/categories.php, or (6) plugins/search/sections.php; or (7) the email parameter in database/table/user.php, which is not properly handled by the check function.

Vulnerable Configurations

Part Description Count
Application
Joomla
1

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/54195/joomla150beta-sql.txt
idPACKETSTORM:54195
last seen2016-12-05
published2007-02-06
reporterOmid
sourcehttps://packetstormsecurity.com/files/54195/joomla150beta-sql.txt.html
titlejoomla150beta-sql.txt