Joomla! JQuarks Component SQL Injection Vulnerability
BID:38203
Info
Joomla! JQuarks Component SQL Injection Vulnerability
| Bugtraq ID: | 38203 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-0692 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2009 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | The vendor |
| Vulnerable: |
IP-Tech JQuarks 0.2.3 IP-Tech JQuarks 0.2.2 |
| Not Vulnerable: |
IP-Tech JQuarks 0.2.4 |
Discussion
Joomla! JQuarks Component SQL Injection Vulnerability
The JQuarks component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The JQuarks component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
Joomla! JQuarks Component SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Joomla! JQuarks Component SQL Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
IP-Tech JQuarks 0.2.2
IP-Tech JQuarks 0.2.3
Solution:
Updates are available. Please see the references for more information.
IP-Tech JQuarks 0.2.2
-
IP-Tech JQuarks 0.2.4
http://www.iptechinside.com/labs/versions/show/6
IP-Tech JQuarks 0.2.3
-
IP-Tech JQuarks 0.2.4
http://www.iptechinside.com/labs/versions/show/6
References
Joomla! JQuarks Component SQL Injection Vulnerability
References:
References:
- News & updates from JQuarks (IP-Tech)