yvComment Joomla! Component 'ArticleID' Parameter SQL Injection Vulnerability
BID:29596
Info
yvComment Joomla! Component 'ArticleID' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 29596 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2692 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 08 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | His0k4 |
| Vulnerable: |
yvComment yvComment 1.16 |
| Not Vulnerable: |
yvComment yvComment 1.16.1 |
Discussion
yvComment Joomla! Component 'ArticleID' Parameter SQL Injection Vulnerability
The yvComment component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
yvComment 1.16 and prior versions are vulnerable.
The yvComment component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
yvComment 1.16 and prior versions are vulnerable.
Exploit / POC
yvComment Joomla! Component 'ArticleID' Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following proof of concept is available:
Attackers can use a browser to exploit this issue.
The following proof of concept is available:
Solution / Fix
yvComment Joomla! Component 'ArticleID' Parameter SQL Injection Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
yvComment yvComment 1.16
Solution:
The vendor released an update to address this issue. Please see the references for more information.
yvComment yvComment 1.16
-
yvComment yvCommentComponent1.16.001.zip
http://joomlacode.org/gf/download/frsrelease/7781/27655/yvCommentCompo nent1.16.001.zip
References
yvComment Joomla! Component 'ArticleID' Parameter SQL Injection Vulnerability
References:
References:
- yvComment Home Page (yvComment)