CVE-2008-6653

SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
VendorProductVersion
wh-comcom_webhosting
𝑥
≤ 1.1
wh-comcom_webhosting
0.5:beta
wh-comcom_webhosting
0.5.3:beta
wh-comcom_webhosting
0.5.4:beta
wh-comcom_webhosting
0.5.5:beta
wh-comcom_webhosting
0.5.6:beta
wh-comcom_webhosting
1.0:stable
wh-comcom_webhosting
1.0.1:stable
wh-comcom_webhosting
1.1:alpha
wh-comcom_webhosting
1.1:beta
wh-comcom_webhosting
1.1:rc1
wh-comcom_webhosting
1.1:rc2
wh-comcom_webhosting
1.1:rc3
wh-comcom_webhosting
1.1:rc4
wh-comcom_webhosting
1.1:rc5
𝑥
= Vulnerable software versions