6.8
CVSSv2

CVE-2010-4517

Published: 09/12/2010 Updated: 10/12/2010
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the JExtensions JE Auto (com_jeauto) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote malicious users to execute arbitrary SQL commands via the char parameter in an item action to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

harmistechnology com_jeauto 1.0

Exploits

JE Auto 10 SQL Injection Vulnerability Name JE Auto Vendor joomlaextensionscoin/extensions/components/je-autohtml Versions Affected 10 Author Salvatore Fresta aka Drosophila Website wwwsalvatorefrestanet Contact salvatorefresta [at] gmail [dot] com Date ...