CVE-2009-3215

S

QL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! 1.0.x, allows remote attackers to execute arbitrary SQL commands via the parent parameter.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:php-shop-system:ixxo_cart:*:*:*:*:*:*:*:*
OR cpe:2.3:a:joomla:joomla:1.0:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.8:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.9:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.10:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.11:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.12:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.13:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.14:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.03:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5:rc1:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5:rc2:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5:rc3:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.0:beta:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.0:beta1:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.0:beta2:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.0:rc1:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.2:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.3:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.4:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.5:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.6:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.7:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.8:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.9:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.10:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5rc4:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.8.1:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:php-shop-system:ixxo_cart:*:*:standalone:*:*:*:*:*

History

21 Nov 2024, 01:06

Type Values Removed Values Added
References () http://secunia.com/advisories/36009 - Vendor Advisory () http://secunia.com/advisories/36009 - Vendor Advisory
References () http://www.davidsopas.com/2009/07/25/ixxo-cart-standalone-and-joomla-component-sql-injection/ - () http://www.davidsopas.com/2009/07/25/ixxo-cart-standalone-and-joomla-component-sql-injection/ -
References () http://www.exploit-db.com/exploits/9276 - () http://www.exploit-db.com/exploits/9276 -
References () http://www.securityfocus.com/archive/1/505266/100/0/threaded - () http://www.securityfocus.com/archive/1/505266/100/0/threaded -
References () http://www.securityfocus.com/bid/35810 - Exploit, Patch () http://www.securityfocus.com/bid/35810 - Exploit, Patch

Information

Published : 2009-09-16 19:30

Updated : 2025-04-09 00:30


NVD link : CVE-2009-3215

Mitre link : CVE-2009-3215

CVE.ORG link : CVE-2009-3215


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')