6.8
CVSSv2

CVE-2009-4199

Published: 04/12/2009 Updated: 19/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in the Mambo Resident (aka Mos Res or com_mosres) component 1.0f for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote malicious users to execute arbitrary SQL commands via the (1) property_uid parameter in a viewproperty action to index.php and the (2) regID parameter in a showregion action to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

mamboforge com_mosres 1.0f

Exploits

================================================================================== Joomla Component com_mosres (property_uid) SQL injection Vulnerability ================================================================================== ################################### ...