Security Advisory

CVE-2010-0610

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2010-02-11 17:00:00
Last updated 2024-08-07 00:52:19
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Multiple SQL injection vulnerabilities in the Photoblog (com_photoblog) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the blog parameter in an images action to index.php. NOTE: a separate vector for the id parameter to detail.php may also exist.