iJoomla Archive Component 'catid' Parameter SQL Injection Vulnerability
BID:34011
Info
iJoomla Archive Component 'catid' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 34011 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 05 2009 12:00AM |
| Updated: | Mar 27 2009 08:06PM |
| Credit: | Mountassif Moad |
| Vulnerable: |
iJoomla Archive 0 |
| Not Vulnerable: | |
Discussion
iJoomla Archive Component 'catid' Parameter SQL Injection Vulnerability
iJoomla Archive is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
iJoomla Archive is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
iJoomla Archive Component 'catid' Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following exploit code is available:
Attackers can use a browser to exploit this issue.
The following exploit code is available:
Solution / Fix
iJoomla Archive Component 'catid' Parameter SQL Injection Vulnerability
Solution:
The vendor has released updates. Please contact the vendor for details.
Solution:
The vendor has released updates. Please contact the vendor for details.
References
iJoomla Archive Component 'catid' Parameter SQL Injection Vulnerability
References:
References:
- Vendor Homepage (iJoomla)