Description
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.5 allows remote attackers to execute arbitrary SQL commands via the list[select] parameter to index.php.
Remediation
References
Related Vulnerabilities
Python Improper Input Validation Vulnerability (CVE-2018-20852)
Joomla Session Fixation Vulnerability (CVE-2010-1434)
Craft CMS Server-Side Request Forgery (SSRF) Vulnerability (CVE-2026-27129)
Envoy Wrong DOWNSTREAM_REMOTE_ADDRESS logged Issue (CVE-2020-35470)
Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2020-12605)