Security Advisory
CVE-2009-4474
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
SQL injection vulnerability in the Mike de Boer zoom (com_zoom) component 2.0 for Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.