Vulnerability Database

296,147

Total vulnerabilities in the database

CVE-2010-4166

Multiple SQL injection vulnerabilities in Joomla! 1.5.x before 1.5.22 allow remote attackers to execute arbitrary SQL commands via (1) the filter_order parameter in a com_weblinks category action to index.php, (2) the filter_order_Dir parameter in a com_weblinks category action to index.php, or (3) the filter_order_Dir parameter in a com_messages action to administrator/index.php.

  • Published: Jan 18, 2011
  • Updated: Apr 13, 2023
  • CVE: CVE-2010-4166
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/Au:N/C:P/I:P/A:P

CWEs:

OWASP TOP 10:

Software From Fixed in
Joomla / joomla 1.5.11 1.5.11.x
Joomla / joomla 1.5.13 1.5.13.x
Joomla / joomla 1.5.3 1.5.3.x
Joomla / joomla 1.5.2 1.5.2.x
Joomla / joomla 1.5.9 1.5.9.x
Joomla / joomla 1.5.18 1.5.18.x
Joomla / joomla 1.5.16 1.5.16.x
Joomla / joomla 1.5.4 1.5.4.x
Joomla / joomla 1.5.10 1.5.10.x
Joomla / joomla 1.5.7 1.5.7.x
Joomla / joomla 1.5.0 1.5.0.x
Joomla / joomla 1.5.15 1.5.15.x
Joomla / joomla 1.5.6 1.5.6.x
Joomla / joomla 1.5.1 1.5.1.x
Joomla / joomla 1.5.17 1.5.17.x
Joomla / joomla 1.5.8 1.5.8.x
Joomla / joomla 1.5.19 1.5.19.x
Joomla / joomla 1.5.21 1.5.21.x
Joomla / joomla 1.5.12 1.5.12.x
Joomla / joomla 1.5.5 1.5.5.x
Joomla / joomla 1.5.20 1.5.20.x
Joomla / joomla 1.5.15-rc 1.5.15-rc.x
Joomla / joomla 1.5.14 1.5.14.x