CVE-2010-4166

Multiple SQL injection vulnerabilities in Joomla! 1.5.x before 1.5.22 allow remote attackers to execute arbitrary SQL commands via (1) the filter_order parameter in a com_weblinks category action to index.php, (2) the filter_order_Dir parameter in a com_weblinks category action to index.php, or (3) the filter_order_Dir parameter in a com_messages action to administrator/index.php.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
VendorProductVersion
joomlajoomla\!
1.5.0
joomlajoomla\!
1.5.1
joomlajoomla\!
1.5.2
joomlajoomla\!
1.5.3
joomlajoomla\!
1.5.4
joomlajoomla\!
1.5.5
joomlajoomla\!
1.5.6
joomlajoomla\!
1.5.7
joomlajoomla\!
1.5.8
joomlajoomla\!
1.5.9
joomlajoomla\!
1.5.10
joomlajoomla\!
1.5.11
joomlajoomla\!
1.5.12
joomlajoomla\!
1.5.13
joomlajoomla\!
1.5.14
joomlajoomla\!
1.5.15
joomlajoomla\!
1.5.15:rc
joomlajoomla\!
1.5.16
joomlajoomla\!
1.5.17
joomlajoomla\!
1.5.18
joomlajoomla\!
1.5.19
joomlajoomla\!
1.5.20
joomlajoomla\!
1.5.21
𝑥
= Vulnerable software versions