CVE-2008-6653
07.04.2009, 14:17
SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
| Vendor | Product | Version |
|---|---|---|
| wh-com | com_webhosting | 𝑥 ≤ 1.1 |
| wh-com | com_webhosting | 0.5:beta |
| wh-com | com_webhosting | 0.5.3:beta |
| wh-com | com_webhosting | 0.5.4:beta |
| wh-com | com_webhosting | 0.5.5:beta |
| wh-com | com_webhosting | 0.5.6:beta |
| wh-com | com_webhosting | 1.0:stable |
| wh-com | com_webhosting | 1.0.1:stable |
| wh-com | com_webhosting | 1.1:alpha |
| wh-com | com_webhosting | 1.1:beta |
| wh-com | com_webhosting | 1.1:rc1 |
| wh-com | com_webhosting | 1.1:rc2 |
| wh-com | com_webhosting | 1.1:rc3 |
| wh-com | com_webhosting | 1.1:rc4 |
| wh-com | com_webhosting | 1.1:rc5 |
𝑥
= Vulnerable software versions
References