Vulnerabilities > Joomla > High

DATE CVE VULNERABILITY TITLE RISK
2008-02-15 CVE-2008-0801 SQL Injection vulnerability in Paxxgallery COM Paxxgallery 0.2
SQL injection vulnerability in index.php in the PAXXGallery (com_paxxgallery) 0.2 component for Mambo and Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the iid parameter in a view action, and possibly (2) the userid parameter.
network
low complexity
paxxgallery joomla mambo-foundation CWE-89
7.5
2008-02-15 CVE-2008-0800 SQL Injection vulnerability in Joomla COM Mcquiz 0.9
SQL injection vulnerability in index.php in the McQuiz (com_mcquiz) 0.9 Final component for Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action.
network
low complexity
joomla CWE-89
7.5
2008-02-15 CVE-2008-0799 SQL Injection vulnerability in multiple products
SQL injection vulnerability in index.php in the Quiz (com_quiz) 0.81 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action.
network
low complexity
joomla mambo CWE-89
7.5
2008-02-15 CVE-2008-0795 SQL Injection vulnerability in multiple products
SQL injection vulnerability in index.php in the MGFi XfaQ (com_xfaq) 1.2 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an answer action.
network
low complexity
joomla mambo mgfi CWE-89
7.5
2008-02-14 CVE-2008-0773 SQL Injection vulnerability in multiple products
SQL injection vulnerability in Phil Taylor Comments (com_comments, aka Review Script) 0.5.8.5g and earlier component for Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
joomla mambo phil-taylor CWE-89
7.5
2008-02-14 CVE-2008-0772 SQL Injection vulnerability in multiple products
SQL injection vulnerability in index.php in the com_doc component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the sid parameter in a view task.
network
low complexity
joomla mambo CWE-89
7.5
2008-02-13 CVE-2008-0762 SQL Injection vulnerability in Joomla COM Iomezun
SQL injection vulnerability in index.php in the com_iomezun component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit action.
network
low complexity
joomla CWE-89
7.5
2008-02-13 CVE-2008-0761 SQL Injection vulnerability in Joomla COM Pcchess
SQL injection vulnerability in index.php in the Prince Clan Chess Club (com_pcchess) 0.8 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a players action.
network
low complexity
joomla CWE-89
7.5
2008-02-13 CVE-2008-0754 SQL Injection vulnerability in Joomla COM Rapidrecipe 1.6.5
Multiple SQL injection vulnerabilities in index.php in the Rapid Recipe (com_rapidrecipe) 1.6.5 component for Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a showuser action or (2) the category_id parameter in a viewcategorysrecipes action.
network
low complexity
joomla CWE-89
7.5
2008-02-13 CVE-2008-0752 SQL Injection vulnerability in multiple products
SQL injection vulnerability in index.php in the Neogallery (com_neogallery) 1.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show action.
network
low complexity
joomla mambo CWE-89
7.5