VXDate Component for Joomla! Cross-Site Scripting and SQL-Injection Vulnerabilities
BID:38788
Info
VXDate Component for Joomla! Cross-Site Scripting and SQL-Injection Vulnerabilities
| Bugtraq ID: | 38788 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 17 2010 12:00AM |
| Updated: | Mar 17 2010 12:00AM |
| Credit: | MustLive |
| Vulnerable: |
VXDate VXDate 0 |
| Not Vulnerable: | |
Discussion
VXDate Component for Joomla! Cross-Site Scripting and SQL-Injection Vulnerabilities
VXDate Component for Joomla! is prone to a cross-site scripting vulnerability and an SQL-injection vulnerability because the application fails to sufficiently sanitize user-supplied input.
A successful exploit may allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
These issues affect unknown versions of VXDate. This BID will be updated when more details become available.
VXDate Component for Joomla! is prone to a cross-site scripting vulnerability and an SQL-injection vulnerability because the application fails to sufficiently sanitize user-supplied input.
A successful exploit may allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
These issues affect unknown versions of VXDate. This BID will be updated when more details become available.
Solution / Fix
VXDate Component for Joomla! Cross-Site Scripting and SQL-Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
VXDate Component for Joomla! Cross-Site Scripting and SQL-Injection Vulnerabilities
References:
References:
- Joomla! Homepage (Joomla!)
- VXDate Homepage (VXDate)
- Vulnerabilities in VXDate for Joomla ("MustLive"
)