Информационная безопасность
[RU] switch to
English Version



CVECVE-2006-7010
СтатусCandidate
ОписаниеThe mosgetparam implementation in Joomla! before 1.0.10, does not set a variable's data type to integer when the variable's default value is numeric, which has unspecified impact and attack vectors, which may permit SQL injection attacks.
ВажностьHigh
CVSS score7
CVSS vector(AV:R/AC:L/Au:NR/C:P/I:P/A:P/B:N)
PhaseAssigned (12.02.2007)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-7010
ReferencesCONFIRM : http://www.joomla.org/content/view/1510/74/
 OSVDB : 26916
 SECUNIA : 20874
SecurityVulns:Ежедневная сводка ошибок в Web-приложениях (PHP, ASP, JSP, CGI, Perl )

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server