CVE-2008-1505 – Joomla! Component custompages 1.1 - Remote File Inclusion
https://notcve.org/view.php?id=CVE-2008-1505
PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the cpage parameter to index.php. Vulnerabilidad de inclusión de archivo PHP remoto en SSTREAMTV custompages (com_custompages) 1.1 y componentes anteriores para Joomla! permiten a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro cpage de index.php. • https://www.exploit-db.com/exploits/5294 http://secunia.com/advisories/29520 http://www.securityfocus.com/bid/28409 https://exchange.xforce.ibmcloud.com/vulnerabilities/41396 • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2008-1465 – Joomla! Component Restaurante 1.0 - 'id' SQL Injection
https://notcve.org/view.php?id=CVE-2008-1465
SQL injection vulnerability in the Detodas Restaurante (com_restaurante) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php, a different product than CVE-2008-0562. Vulnerabilidad de inyección SQL en el componente Detodas Restaurante (com_restaurante) 1.0 para Mambo y Joomla! permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro id en una acción detail (detalle) a index.php, un producto distinto a CVE-2008-0562. • https://www.exploit-db.com/exploits/5280 http://secunia.com/advisories/29471 http://www.securityfocus.com/bid/28324 https://exchange.xforce.ibmcloud.com/vulnerabilities/41283 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2008-1459 – Joomla! Component Alberghi 2.1.3 - 'id' SQL Injection
https://notcve.org/view.php?id=CVE-2008-1459
SQL injection vulnerability in the Alberghi (com_alberghi) 2.1.3 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. Vulnerabilidad de inyección SQL en el componente Alberghi (com_alberghi) 2.1.3 y anteriores para Mambo y Joomla! permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro id en una acción detail (detalle) a index.php. • https://www.exploit-db.com/exploits/5278 http://secunia.com/advisories/29473 http://www.securityfocus.com/bid/28331 https://exchange.xforce.ibmcloud.com/vulnerabilities/41285 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2008-1460 – Joomla! Component joovideo 1.2.2 - 'id' SQL Injection
https://notcve.org/view.php?id=CVE-2008-1460
SQL injection vulnerability in the Joovideo (com_joovideo) 1.0 and 1.2.2 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. Vulnerabilidad de inyección SQL en el componente Joovideo (com_joovideo) 1.0 y 1.2.2 para Mambo and Joomla! permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro id en una acción detail (detalle) a index.php. • https://www.exploit-db.com/exploits/5277 http://secunia.com/advisories/29474 http://www.securityfocus.com/bid/28318 https://exchange.xforce.ibmcloud.com/vulnerabilities/41279 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2008-0829 – Joomla! Component jooget 2.6.8 - SQL Injection
https://notcve.org/view.php?id=CVE-2008-0829
SQL injection vulnerability in jooget.php in the Joomlapixel Jooget! (com_jooget) 2.6.8 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail task. Vulnerabilidad de inyección SQL en jooget.php del componente Joomlapixel Jooget! (com_jooget) 2.6.8 para Joomla! • https://www.exploit-db.com/exploits/5132 http://forum.joomlaitalia.com/index.php?topic=388.0 http://members.joomlapixel.eu/download/componenti/patch-jooget-2.6.8-sql-injection/details.html http://secunia.com/advisories/28998 http://www.securityfocus.com/bid/27836 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •