CVE-2009-2554
Joomla! Component Jobline 1.3.1 - Blind SQL Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
SQL injection vulnerability in the search method in jobline.class.php in Jobline (com_jobline) 1.1.2.2, 1.3.1, and possibly earlier versions, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the search parameter in a results action to index.php, which invokes the search method from the searchJobPostings function in jobline.php.
Vulnerabilidad de inyección SQL en el método de búsqueda en jobline.class.php en el componente Jobline (com_jobline) v1.1.2.2, v1.3.1, y posiblemente versiones previas, para Joomla!, permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro de búsqueda en una acción "results" al index.php, que invoca al método de búsqueda desde la función searchJobPostings en jobline.php
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-07-17 First Exploit
- 2009-07-20 CVE Reserved
- 2009-07-20 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/51811 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/9187 | 2009-07-17 | |
http://www.exploit-db.com/exploits/9187 | 2024-08-07 | |
http://www.securityfocus.com/bid/35728 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/35877 | 2017-09-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Olle Johansson Search vendor "Olle Johansson" | Jobline Search vendor "Olle Johansson" for product "Jobline" | 1.1.2.2 Search vendor "Olle Johansson" for product "Jobline" and version "1.1.2.2" | - |
Affected
| in | Joomla Search vendor "Joomla" | Joomla Search vendor "Joomla" for product "Joomla" | * | - |
Safe
|
Olle Johansson Search vendor "Olle Johansson" | Jobline Search vendor "Olle Johansson" for product "Jobline" | 1.3.1 Search vendor "Olle Johansson" for product "Jobline" and version "1.3.1" | - |
Affected
| in | Joomla Search vendor "Joomla" | Joomla Search vendor "Joomla" for product "Joomla" | * | - |
Safe
|