CVE-2009-2395

SQL injection vulnerability in the K2 (com_k2) component 1.0.1 Beta and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter in an itemlist action to index.php.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
Affected Products (NVD)
VendorProductVersion
joomlaworkscom_k2
𝑥
≤ 1.0.1
𝑥
= Vulnerable software versions
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
flash-player
suse enterprise desktop 12
11.2.202.406-1.3
fixed
suse enterprise desktop 12 SP1
11.2.202.548-111.1
fixed
suse enterprise sap 12
11.2.202.406-1.3
fixed
suse enterprise sap 12 SP1
11.2.202.548-111.1
fixed
suse enterprise server 12
11.2.202.406-1.3
fixed
suse enterprise server 12 SP1
11.2.202.548-111.1
fixed
suse enterprise workstation 12
11.2.202.406-1.3
fixed
suse enterprise workstation 12 SP1
11.2.202.548-111.1
fixed
flash-player-gnome
suse enterprise desktop 12
11.2.202.406-1.3
fixed
suse enterprise desktop 12 SP1
11.2.202.548-111.1
fixed
suse enterprise sap 12
11.2.202.406-1.3
fixed
suse enterprise sap 12 SP1
11.2.202.548-111.1
fixed
suse enterprise server 12
11.2.202.406-1.3
fixed
suse enterprise server 12 SP1
11.2.202.548-111.1
fixed
suse enterprise workstation 12
11.2.202.406-1.3
fixed
suse enterprise workstation 12 SP1
11.2.202.548-111.1
fixed