CVE-2009-4625

BF Survey Pro Free <1.2.6 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in the updateOnePage function in components/com_bfsurvey_pro/controller.php in BF Survey Pro Free (com_bfsurvey_profree) 1.2.4, and other versions before 1.2.6, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the table parameter in an updateOnePage action to index.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by jdc · phpwebappsphp
https://www.exploit-db.com/exploits/9601

Scores

EPSS 0.0019
EPSS Percentile 41.1%

Details

CWE
CWE-89
Status published
Products (2)
tamlyncreative/com_bfsurvey_profree 1.2.4
tamlyncreative/com_bfsurvey_profree < 1.2.5
Published Jan 18, 2010
Tracked Since Feb 18, 2026