Unrated severityNVD Advisory· Published Apr 19, 2010· Updated Apr 29, 2026
CVE-2010-1477
CVE-2010-1477
Description
SQL injection vulnerability in the SermonSpeaker (com_sermonspeaker) component before 3.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a latest_sermons action to index.php.
Affected products
2cpe:2.3:a:martin_hess:com_sermonspeaker:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:martin_hess:com_sermonspeaker:*:*:*:*:*:*:*:*range: <=3.2.0
- cpe:2.3:a:martin_hess:com_sermonspeaker:2.9:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- joomlacode.org/gf/project/sermon_speaker/forum/nvdPatch
- joomlacode.org/gf/project/sermon_speaker/news/nvdPatch
- packetstormsecurity.org/1004-exploits/joomlasermonspeaker-sql.txtnvdExploit
- www.exploit-db.com/exploits/12184nvdExploit
- www.securityfocus.com/bid/39410nvdExploit
- secunia.com/advisories/39385nvdVendor Advisory
News mentions
0No linked articles in our index yet.