Vulnerabilities > Martin Hess > COM Sermonspeaker > 2.9

DATE CVE VULNERABILITY TITLE RISK
2010-04-19 CVE-2010-1477 SQL Injection vulnerability in Martin Hess COM Sermonspeaker 2.9
SQL injection vulnerability in the SermonSpeaker (com_sermonspeaker) component before 3.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a latest_sermons action to index.php.
network
low complexity
martin-hess joomla CWE-89
7.5