CVE-2008-6653

EUVD-2008-6615
SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 41%
Affected Products (NVD)
VendorProductVersion
wh-comcom_webhosting
𝑥
≤ 1.1
wh-comcom_webhosting
0.5:beta
wh-comcom_webhosting
0.5.3:beta
wh-comcom_webhosting
0.5.4:beta
wh-comcom_webhosting
0.5.5:beta
wh-comcom_webhosting
0.5.6:beta
wh-comcom_webhosting
1.0:stable
wh-comcom_webhosting
1.0.1:stable
wh-comcom_webhosting
1.1:alpha
wh-comcom_webhosting
1.1:beta
wh-comcom_webhosting
1.1:rc1
wh-comcom_webhosting
1.1:rc2
wh-comcom_webhosting
1.1:rc3
wh-comcom_webhosting
1.1:rc4
wh-comcom_webhosting
1.1:rc5
𝑥
= Vulnerable software versions