SQL injection vulnerability in (1) Joomla! 1.0.11 and 1.5 Beta, and (2) Mambo 4.6.1, allows remote attackers to execute arbitrary SQL commands via the id parameter when cancelling content editing.
| Software | From | Fixed in |
|---|---|---|
| mambo / mambo | 4.6.1 | 4.6.1.x |
| Joomla / joomla | 1.5.0_beta | 1.5.0_beta.x |
| Joomla / joomla | 1.0.11 | 1.0.11.x |