Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2009-3971

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2009-3971
Last Modified 12 Dec 2011 12:00:00
Published 18 Nov 2009 06:30:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2009-3971

Summary

SQL injection vulnerability in the jTips (com_jtips) component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a ladder action to index.php.

Vulnerable Systems

Application

  • Com Jtips 1.0.7

  • Com Jtips 1.0.9

  • Jtips 1.0.7

  • Jtips 1.0.9


References

VUPEN - ADV-2009-2405

BID - 36123

MILW0RM - 9504


Last Updated: 27 May 2016 10:57:51