7.5
CVSSv2

CVE-2009-2395

Published: 09/07/2009 Updated: 19/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the K2 (com_k2) component 1.0.1 Beta and previous versions for Joomla! allows remote malicious users to execute arbitrary SQL commands via the category parameter in an itemlist action to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

joomlaworks com_k2

Exploits

---------------------------------------------------------------------- Joomla Component com_k2 (sectionid) SQL injection Vulnerability ---------------------------------------------------------------------- ################################################### [+] Author : Chip D3 Bi0s [+] Email : chipdebios[alt+64]gmailcom [+] ...
Joomla K2 component version 290 suffers from database disclosure and remote SQL injection vulnerabilities ...