CVE-2010-0610
Multiple SQL injection vulnerabilities in the Photoblog (com_photoblog) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the blog parameter in an images action to index.php.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.97%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in the Photoblog (com_photoblog) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the blog parameter in an images action to index.php. NOTE: a separate vector for the id parameter to detail.php may also exist.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.97% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- webguerilla/com photoblog
- Source
- cve@mitre.org
References
- http://packetstormsecurity.org/1002-exploits/joomlaphotoblog-bsql.txtExploit
- http://www.exploit-db.com/exploits/11337Exploit
- http://www.securityfocus.com/bid/38136Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56135
- http://packetstormsecurity.org/1002-exploits/joomlaphotoblog-bsql.txtExploit
- http://www.exploit-db.com/exploits/11337Exploit
- http://www.securityfocus.com/bid/38136Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56135
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.