Description
SQL injection vulnerability in index.php in the eWriting (com_ewriting) 1.2.1 module for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a selectcat action.
Affected products
- ewriting / ewriting1.2.1 – 1.2.1
- Joomla! / com_ewriting1.2.1 – 1.2.1
- Mambo / com_ewriting1.2.1 – 1.2.1