CVE-2008-6068 – Joomla! Component JoomlaDate 1.2 - 'user' SQL Injection
https://notcve.org/view.php?id=CVE-2008-6068
SQL injection vulnerability in the JoomlaDate (com_joomladate) component 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a viewProfile action to index.php. Vulnerabilidad de inyección SQL en el componente JoomlaDate (com_joomladate) v1.2 para Joomla! permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámentro "user" en una acción viewProfile en index.php. • https://www.exploit-db.com/exploits/5748 http://secunia.com/advisories/30441 https://exchange.xforce.ibmcloud.com/vulnerabilities/42873 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2009-0421 – Joomla! Component com_Eventing 1.6.x - Blind SQL Injection
https://notcve.org/view.php?id=CVE-2009-0421
SQL injection vulnerability in the Eventing (com_eventing) 1.6.x component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. Vulnerabilidad de inyección SQL en el componente para Joomla! Eventing (com_eventing) v1.6.x; permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro catid de index.php. • https://www.exploit-db.com/exploits/7793 http://secunia.com/advisories/33563 http://www.securityfocus.com/bid/33296 https://exchange.xforce.ibmcloud.com/vulnerabilities/48016 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2009-0420 – Joomla! Component RD-Autos 1.5.5 - SQL Injection
https://notcve.org/view.php?id=CVE-2009-0420
SQL injection vulnerability in the RD-Autos (com_rdautos) 1.5.5 Stable component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. Vulnerabilidad de inyección SQL en el componente RD-Autos (com_rdautos) v1.5.5 Stable para Joomla! permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro id de index.php. • https://www.exploit-db.com/exploits/7795 http://secunia.com/advisories/33562 http://www.securityfocus.com/bid/33297 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2008-6050 – Joomla! Component Tech Article 1.x - SQL Injection
https://notcve.org/view.php?id=CVE-2008-6050
SQL injection vulnerability in the Tech Articles (com_tech_article) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the item parameter to index.php. Vulnerabilidad de inyección SQL en el componente Tech Articles (com_tech_article) v1.0 para Joomla! permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro "item" en el index.php. • https://www.exploit-db.com/exploits/7504 http://www.securityfocus.com/bid/32897 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2009-0380 – Mambo Component SOBI2 RC 2.8.2 - SQL Injection
https://notcve.org/view.php?id=CVE-2009-0380
SQL injection vulnerability in the Sigsiu Online Business Index 2 (SOBI2, com_sobi2) RC 2.8.2 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the bid parameter in a showbiz action to index.php, a different vector than CVE-2008-0607. NOTE: CVE disputes this issue, since neither "showbiz" nor "bid" appears in the source code for SOBI2 ** CUESTIONADA ** Una vulnerabilidad de inyección de SQL en el componente de Joomla! y Mambo Sigsiu Online Business Index 2 (SOBI2, com_sobi2) RC 2.8.2 permite a atacantes remotos ejecutar comandos SQL arbitrarios a través de parámetro bid en una acción showbiz a index.php, un vector diferente que CVE-2008-0607. NOTA: CVE discute de este problema, ya que ni "showbiz" ni "bid" aparece en el código fuente de SOBI2. • https://www.exploit-db.com/exploits/7841 http://www.attrition.org/pipermail/vim/2009-January/002136.html http://www.securityfocus.com/bid/33378 https://exchange.xforce.ibmcloud.com/vulnerabilities/48131 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •