VYPR

by Joomla

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2009-14990.030.00May 1, 2009SQL injection vulnerability in the MailTo (aka com_mailto) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the article parameter in index.php. NOTE: SecurityFocus states that this issue has been disputed by the vendor.
CVE-2008-41030.000.00Sep 18, 2008The mailto (aka com_mailto) component in Joomla! 1.5 before 1.5.7 sends e-mail messages without validating the URL, which allows remote attackers to transmit spam.