Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x through 4.1.7, and possibly 3.x, for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) listid or (2) themeid parameter to index.php.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2014-07-21T14:00:00

Updated: 2015-04-29T18:57:00

Reserved: 2014-07-14T00:00:00


Link: CVE-2014-4960

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2014-07-21T14:55:06.800

Modified: 2015-10-06T02:37:30.113


Link: CVE-2014-4960

JSON object: View

cve-icon Redhat Information

No data.

CWE