CVE-2010-1522
Joomla BookLibrary Four SQL Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple SQL injection vulnerabilities in the BookLibrary Basic (com_booklibrary) component 1.5.3 before 1.5.3_2010_06_20 for Joomla! allow remote attackers to execute arbitrary SQL commands via the bid[] parameter in a (1) lend_request or (2) save_lend_request action to index.php, the id parameter in a (3) mdownload or (4) downitsf action to index.php, or (5) the searchtext parameter in a search action to index.php.
Múltiples vulnerabilidades de inyección SQL en el componente BookLibrary Basic (com_booklibrary) v1.5.3 anterior a v1.5.3_2010_06_20 para Joomla! permiten a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro bid[] en una acción (1) lend_request o (2) save_lend_request en index.php; el parámetro id en una acción (3) mdownload o (4) downitsf en index.php; o (5) el parámetro searchtext en una acción search en index.php.
Secunia Research has discovered multiple vulnerabilities in the BookLibrary component for Joomla, which can be exploited by malicious people to conduct SQL injection attacks. BookLibrary version 1.5.3 Basic is affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-04-26 CVE Reserved
- 2010-07-01 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://osvdb.org/65879 | Vdb Entry | |
http://www.securityfocus.com/archive/1/512094/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/41264 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/59966 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/40131 | 2018-10-10 | |
http://secunia.com/secunia_research/2010-84 | 2018-10-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ordasoft Search vendor "Ordasoft" | Com Booklibrary Search vendor "Ordasoft" for product "Com Booklibrary" | 1.5.3 Search vendor "Ordasoft" for product "Com Booklibrary" and version "1.5.3" | - |
Affected
| in | Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | * | - |
Safe
|