BSQ Sitestats Joomla Component HTML Injection and SQL Injection Vulnerabilities
BID:20614
Info
BSQ Sitestats Joomla Component HTML Injection and SQL Injection Vulnerabilities
| Bugtraq ID: | 20614 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2006 12:00AM |
| Updated: | Oct 19 2006 09:24PM |
| Credit: | Sven Krewitt of Secunia Research is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Joomla BSQ Sitestats 2.2.1 Joomla BSQ Sitestats 1.8 |
| Not Vulnerable: |
Joomla BSQ Sitestats 2.2.2 |
Discussion
BSQ Sitestats Joomla Component HTML Injection and SQL Injection Vulnerabilities
BSQ Sitestats is prone to multiple input-validation vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to steal cookie-based authentication credentials, control how the site is rendered to the user, access or modify data, or exploit latent vulnerabilities in the underlying database implementation. Other attacks are also possible.
Versions 1.8.0 and 2.2.1 are vulnerable; other versions may also be affected.
The issues reported may be related to previous vulnerabilities documented in BID 20267 (BSQ Sitestats Joomla Component Multiple Input Validation Vulnerabilities).
BSQ Sitestats is prone to multiple input-validation vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to steal cookie-based authentication credentials, control how the site is rendered to the user, access or modify data, or exploit latent vulnerabilities in the underlying database implementation. Other attacks are also possible.
Versions 1.8.0 and 2.2.1 are vulnerable; other versions may also be affected.
The issues reported may be related to previous vulnerabilities documented in BID 20267 (BSQ Sitestats Joomla Component Multiple Input Validation Vulnerabilities).
Exploit / POC
BSQ Sitestats Joomla Component HTML Injection and SQL Injection Vulnerabilities
An attacker can exploit these issues via a web client.
An attacker can exploit these issues via a web client.
Solution / Fix
BSQ Sitestats Joomla Component HTML Injection and SQL Injection Vulnerabilities
Solution:
The vendor has released version 2.2.2 to address these issues. Please see the references for more information.
Joomla BSQ Sitestats 1.8
Joomla BSQ Sitestats 2.2.1
Solution:
The vendor has released version 2.2.2 to address these issues. Please see the references for more information.
Joomla BSQ Sitestats 1.8
-
Joomla com_bsq_sitestats_2_2_2
http://developer.joomla.org/sf/frs/do/viewRelease/projects.bsq_sitesta ts/frs.bsq_sitestats_component.com_bsq_sitestats_2_2_2
Joomla BSQ Sitestats 2.2.1
References
BSQ Sitestats Joomla Component HTML Injection and SQL Injection Vulnerabilities
References:
References:
- BSQ Sitestats Homepage (Joomla)
- Secunia Research: Joomla BSQ Sitestats Script Insertion and SQL Injection (Secunia Research)
- Joomla BSQ Sitestats Script Insertion and SQL Injection (Secunia Research)