CVE-2010-0158
Joomla! Component Bamboo Simpla Admin Template - SQL Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
SQL injection vulnerability in the JoomlaBamboo (JB) Simpla Admin template for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to the com_content component, reachable through index.php. NOTE: the vendor disputes this report, saying: "JoomlaBamboo has investigated this report, and it is incorrect. There is no SQL injection vulnerability involving the id parameter in an article view, and there never was. JoomlaBamboo customers have no reason to be concerned about this report.
** DISPUTADA ** Vulnerabilidad de inyección SQL en la plantilla JoomlaBamboo (JB) Simpla Admin para Joomla! permite a atacantes remotos ejecutar comandos SQL arbitrarios a través del parámetro id en una acción de artículo en el componente com_content, accesible mediante index.php. NOTA: el proveedor disputa este informe, diciendo: 'JoomlaBamboo ha investigado este informe, y no es correcto. No hay una vulnerabilidad de inyección SQL que involucra el parámetro id en una visualización de artículos, y nunca hubo. Los clientes de JoomlaBamboo no tiene motivo para preocuparse por este informe.'
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-01-03 First Exploit
- 2010-01-06 CVE Reserved
- 2010-01-06 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.attrition.org/pipermail/vim/2010-February/002319.html | Mailing List | |
http://www.attrition.org/pipermail/vim/2010-February/002320.html | Mailing List |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/10971 | 2010-01-03 | |
http://packetstormsecurity.org/1001-exploits/joomlabamboo-sql.txt | 2024-08-07 | |
http://www.exploit-db.com/exploits/10971 | 2024-08-07 | |
http://www.securityfocus.com/bid/37579 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.vupen.com/english/advisories/2010/0014 | 2024-05-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Joomlabamboo Search vendor "Joomlabamboo" | Jb Simpla Search vendor "Joomlabamboo" for product "Jb Simpla" | * | - |
Affected
| in | Joomla Search vendor "Joomla" | Joomla Search vendor "Joomla" for product "Joomla" | * | - |
Safe
|