7.5
CVSSv2

CVE-2009-4550

Published: 04/01/2010 Updated: 19/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the Kunena Forum (com_kunena) component 1.5.3 and 1.5.4 for Joomla! allows remote malicious users to execute arbitrary SQL commands via the func parameter to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

kunena kunena_forum 1.5.3

kunena kunena_forum 1.5.4

Exploits

<?php ini_set("max_execution_time",0); print_r(' ############################################################################## # # Joomla Kunena Forums (func) Blind SQL Injection Exploit # # MEFISTO aka ilkerkandemir # mefisto [at] hackermail com # (IMT) im ...