GCalendar Joomla! Component 'gcid' Parameter SQL Injection Vulnerability
BID:37141
Info
GCalendar Joomla! Component 'gcid' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 37141 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 27 2009 12:00AM |
| Updated: | Dec 09 2009 06:34PM |
| Credit: | v3n0m |
| Vulnerable: |
G4J GCalendar 2.1.4 |
| Not Vulnerable: | |
Discussion
GCalendar Joomla! Component 'gcid' Parameter SQL Injection Vulnerability
The GCalendar component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
GCalendar 2.1.4 is vulnerable; other versions may also be affected.
The GCalendar component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
GCalendar 2.1.4 is vulnerable; other versions may also be affected.
Exploit / POC
GCalendar Joomla! Component 'gcid' Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following exploit code is available:
Attackers can use a browser to exploit this issue.
The following exploit code is available:
Solution / Fix
GCalendar Joomla! Component 'gcid' Parameter SQL Injection Vulnerability
Solution:
Updates are available. Please see the references for details.
G4J GCalendar 2.1.4
Solution:
Updates are available. Please see the references for details.
G4J GCalendar 2.1.4
-
G4J com_gcalendar_sql_patch.zip
http://g4j.laoneo.net/content/images/fbfiles/files/com_gcalendar_sql_p atch.zip
References
GCalendar Joomla! Component 'gcid' Parameter SQL Injection Vulnerability
References:
References: