CVE-2010-1874
SQL injection vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an agentlisting action to index.php.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.00%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SQL injection vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an agentlisting action to index.php. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.00% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- com-property/com properties
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/39074Vendor Advisory
- http://www.exploit-db.com/exploits/12136Exploit
- http://www.securityfocus.com/bid/39374Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/57765
- http://secunia.com/advisories/39074Vendor Advisory
- http://www.exploit-db.com/exploits/12136Exploit
- http://www.securityfocus.com/bid/39374Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/57765
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.