CVE-2010-4166

Vulnérabilités

CVE-2010-4166

Multiple SQL injection vulnerabilities in Joomla!

HIGH Joomla CMS

Multiple SQL injection vulnerabilities in Joomla! 1.5.x before 1.5.22 allow remote attackers to execute arbitrary SQL commands via (1) the filter_order parameter in a com_weblinks category action to index.php, (2) the filter_order_Dir parameter in a com_weblinks category action to index.php, or (3) the filter_order_Dir parameter in a com_messages action to administrator/index.php.

7.5 Élevée · CVSS 2.0

AV:N/AC:L/Au:N/C:P/I:P/A:P

Score retenu : NVD

SourceSévérité d'origineCVSS
NVDHIGH 7.5 (v2.0)
Produit
Joomla CMS
Corrigée dans
Non précisée
Publiée
18/01/2011
Modifiée
16/06/2026
CWE
CWE-89
  • 1.5.0 – 1.5.0
  • 1.5.1 – 1.5.1
  • 1.5.2 – 1.5.2
  • 1.5.3 – 1.5.3
  • 1.5.4 – 1.5.4
  • 1.5.5 – 1.5.5
  • 1.5.6 – 1.5.6
  • 1.5.7 – 1.5.7
  • 1.5.8 – 1.5.8
  • 1.5.9 – 1.5.9
  • 1.5.10 – 1.5.10
  • 1.5.11 – 1.5.11
10 autres
  • 1.5.12 – 1.5.12
  • 1.5.13 – 1.5.13
  • 1.5.14 – 1.5.14
  • 1.5.15 – 1.5.15
  • 1.5.16 – 1.5.16
  • 1.5.17 – 1.5.17
  • 1.5.18 – 1.5.18
  • 1.5.19 – 1.5.19
  • 1.5.20 – 1.5.20
  • 1.5.21 – 1.5.21

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Détectée via nvd26/09/2026 09:34 UTC