Unrated severityNVD Advisory· Published Jun 9, 2010· Updated Apr 29, 2026
CVE-2010-2255
CVE-2010-2255
Description
SQL injection vulnerability in the BF Survey Pro (com_bfsurvey_pro) component before 1.3.1, BF Survey Pro Free (com_bfsurvey_profree) component 1.2.6, and BF Survey Basic component before 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. NOTE: some of these details are obtained from third party information.
Affected products
3- cpe:2.3:a:tamlyncreative:com_bfsurvey_basic:*:*:*:*:*:*:*:*Range: <=1.1
- cpe:2.3:a:tamlyncreative:com_bfsurvey_pro:*:*:*:*:*:*:*:*Range: <=1.3.0
- cpe:2.3:a:tamlyncreative:com_bfsurvey_profree:1.2.6:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- packetstormsecurity.org/1001-exploits/joomlabfsurveypro-sql.txtnvdExploit
- www.securityfocus.com/bid/37585nvdExploit
- www.tamlyncreative.com.au/software/forum/index.phpnvdExploit
- secunia.com/advisories/37868nvdVendor Advisory
- osvdb.org/61456nvd
News mentions
0No linked articles in our index yet.