Arbitrary SQL Command Execution in Joomla! Club Manager Component

Arbitrary SQL Command Execution in Joomla! Club Manager Component

CVE-2010-4864 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

SQL injection vulnerability in the Club Manager (com_clubmanager) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cm_id parameter in an equip presenta action to index.php.

Learn more about our Web Application Penetration Testing UK.