CVE-2010-2255
09.06.2010, 20:30
SQL injection vulnerability in the BF Survey Pro (com_bfsurvey_pro) component before 1.3.1, BF Survey Pro Free (com_bfsurvey_profree) component 1.2.6, and BF Survey Basic component before 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. NOTE: some of these details are obtained from third party information.
Vendor | Product | Version |
---|---|---|
tamlyncreative | com_bfsurvey_profree | 1.2.6 |
tamlyncreative | com_bfsurvey_pro | 𝑥 ≤ 1.3.0 |
tamlyncreative | com_bfsurvey_basic | 𝑥 ≤ 1.1 |
𝑥
= Vulnerable software versions
References