Multiple SQL injection vulnerabilities in the Kunena component before 3.0.6 for Joomla! allow remote authenticated users to execute arbitrary SQL commands via the index value in an array parameter, as demonstrated by the topics[] parameter in an unfavorite action to index.php.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2014-11-26T15:00:00Z

Updated: 2024-09-16T17:58:37.812Z

Reserved: 2014-11-26T00:00:00Z

Link: CVE-2014-9102

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2014-11-26T15:59:17.997

Modified: 2014-12-05T16:53:55.813

Link: CVE-2014-9102

cve-icon Redhat

No data.