Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 281516 (CVE-2008-6923) - <www-apps/joomla-1.5.15 com_content SQLi (CVE-2008-6923)
Summary: <www-apps/joomla-1.5.15 com_content SQLi (CVE-2008-6923)
Status: RESOLVED FIXED
Alias: CVE-2008-6923
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://nvd.nist.gov/nvd.cfm?cvename=C...
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2009-08-14 22:23 UTC by Alex Legler (RETIRED)
Modified: 2012-01-12 00:26 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alex Legler (RETIRED) archtester gentoo-dev Security 2009-08-14 22:23:04 UTC
CVE-2008-6923 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6923):
  SQL injection vulnerability in the content component (com_content)
  1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL
  commands via the Itemid parameter in a blogcategory action to
  index.php.
Comment 1 Christian Faulhammer (RETIRED) gentoo-dev 2009-12-25 00:38:12 UTC
Security, the current com_content is 1.5.0 in Joomla! 1.5.15.  So this exploit might not effect us.
Comment 2 Sean Amoss (RETIRED) gentoo-dev Security 2012-01-12 00:26:20 UTC
Issued fixed in joomla-1.5.15 added 25 Dec 2009