Joomla! Freestyle FAQs and Freestyle Testimonials Components Unspecified SQL Injection Vulnerability
BID:50338
Info
Joomla! Freestyle FAQs and Freestyle Testimonials Components Unspecified SQL Injection Vulnerability
| Bugtraq ID: | 50338 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 24 2011 12:00AM |
| Updated: | Oct 24 2011 12:00AM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Freestyle Joomla Freestyle Testimonials 1.5.6 Freestyle Joomla Freestyle FAQs 1.5.6 |
| Not Vulnerable: |
Freestyle Joomla Freestyle Testimonials 1.9 Freestyle Joomla Freestyle FAQs 1.9 |
Discussion
Joomla! Freestyle FAQs and Freestyle Testimonials Components Unspecified SQL Injection Vulnerability
The Freestyle FAQs and Freestyle Testimonials components for Joomla! are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Freestyle FAQs 1.5.6 and Freestyle Testimonials 1.5.6 are vulnerable. Other versions may also be affected.
The Freestyle FAQs and Freestyle Testimonials components for Joomla! are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Freestyle FAQs 1.5.6 and Freestyle Testimonials 1.5.6 are vulnerable. Other versions may also be affected.
Exploit / POC
Joomla! Freestyle FAQs and Freestyle Testimonials Components Unspecified SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Joomla! Freestyle FAQs and Freestyle Testimonials Components Unspecified SQL Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Joomla! Freestyle FAQs and Freestyle Testimonials Components Unspecified SQL Injection Vulnerability
References:
References:
- Freestyle FAQs and Testimonials Homepage (Freestyle Joomla)
- Joomla! Homepage (Joomla!)
- Freestyle FAQs and Testimonials 1.9 released (Freestyle Joomla)
- Vulnerable Extensions List (Joomla)