Joomla! JBDiary Component Multiple SQL Injection Vulnerabilities
BID:37936
Info
Joomla! JBDiary Component Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 37936 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 23 2010 12:00AM |
| Updated: | Jan 27 2010 10:21AM |
| Credit: | B-HUNT3|2 |
| Vulnerable: |
Joomla JBDiary 1.6 |
| Not Vulnerable: | |
Discussion
Joomla! JBDiary Component Multiple SQL Injection Vulnerabilities
The JBDiary component for Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The JBDiary component for Joomla! is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Solution / Fix
Joomla! JBDiary Component Multiple SQL Injection Vulnerabilities
Solution:
This application is no longer available or supported by the vendor. Please see the references and contact the vendor for more information.
Solution:
This application is no longer available or supported by the vendor. Please see the references and contact the vendor for more information.