SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11...
Vulnerability Description
SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrary SQL commands via the aid parameter. NOTE: it was later reported that 2.40 is also affected, and that the component can be used in Joomla! in addition to Mambo.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-4456
Credits & Attribution
No credits recorded in the NVD database.
References
- http://securityreason.com/securityalert/3041
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36113
- http://secunia.com/advisories/26556
- http://www.securityfocus.com/archive/1/477232/100/0/threaded
- https://www.exploit-db.com/exploits/4296
- http://www.securityfocus.com/bid/25376
- http://www.securityfocus.com/archive/1/477174/100/0/threaded
More from mambo
View All →Affected Vendor
mambo
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.