Vulnerabilities > Joomla > High

DATE CVE VULNERABILITY TITLE RISK
2009-09-30 CVE-2009-3480 SQL Injection vulnerability in Isygen Icrm Basic 1.4.2.31
SQL injection vulnerability in the iCRM Basic (com_icrmbasic) component 1.4.2.31 for Joomla! allows remote attackers to execute arbitrary SQL commands via the p3 parameter to index.php.
network
low complexity
isygen joomla CWE-89
7.5
2009-09-28 CVE-2009-3446 SQL Injection vulnerability in Rick Estrada COM Mytube 1.0Beta
SQL injection vulnerability in the MyRemote Video Gallery (com_mytube) component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php.
network
low complexity
rick-estrada joomla CWE-89
7.5
2009-09-28 CVE-2009-3443 SQL Injection vulnerability in Fastballproductions COM Fastball 1.1.0/1.2
SQL injection vulnerability in the Fastball (com_fastball) component 1.1.0 through 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the league parameter to index.php.
network
low complexity
fastballproductions joomla CWE-89
7.5
2009-09-28 CVE-2009-3438 SQL Injection vulnerability in Witchakorn Kamolpornwijit COM Facebook
SQL injection vulnerability in the JoomlaFacebook (com_facebook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php.
network
low complexity
witchakorn-kamolpornwijit joomla CWE-89
7.5
2009-09-28 CVE-2009-3434 SQL Injection vulnerability in Onestopjoomla COM Tupinambis 1.0
SQL injection vulnerability in the Tupinambis (com_tupinambis) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a verproyecto action to index.php.
network
low complexity
onestopjoomla joomla mambo CWE-89
7.5
2009-09-25 CVE-2009-3417 SQL Injection vulnerability in Idojoomla COM Idoblog 1.1
SQL injection vulnerability in the IDoBlog (com_idoblog) component 1.1 build 30 for Joomla! allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile action to index.php, a different vector than CVE-2008-2627.
network
low complexity
idojoomla joomla CWE-89
7.5
2009-09-24 CVE-2009-3357 SQL Injection vulnerability in Joomlahbs COM Hbssearch
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) h_id, (2) id, and (3) rid parameters to longDesc.php, and the h_id parameter to (4) detail.php, (5) detail1.php, (6) detail2.php, (7) detail3.php, (8) detail4.php, (9) detail5.php, (10) detail6.php, (11) detail7.php, and (12) detail8.php, different vectors than CVE-2008-5865, CVE-2008-5874, and CVE-2008-5875.
network
low complexity
joomla joomlahbs CWE-89
7.5
2009-09-24 CVE-2009-3342 SQL Injection vulnerability in Alphaplug COM Alphauserpoints 1.5.2
SQL injection vulnerability in frontend/assets/ajax/checkusername.php in the AlphaUserPoints (com_alphauserpoints) component 1.5.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the username2points parameter.
network
low complexity
joomla alphaplug CWE-89
7.5
2009-09-24 CVE-2009-3335 SQL Injection vulnerability in Turtus Turtushout 0.11
SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.
network
low complexity
joomla turtus CWE-89
7.5
2009-09-23 CVE-2009-3334 SQL Injection vulnerability in Lhacky COM Jinc 0.2
SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component (aka JINC or com_jinc) component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a messages action to index.php.
network
low complexity
lhacky joomla CWE-89
7.5