Joomla RSGallery2 Component HTML Injection and SQL Injection Vulnerabilities
BID:54752
Info
Joomla RSGallery2 Component HTML Injection and SQL Injection Vulnerabilities
| Bugtraq ID: | 54752 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-3554 CVE-2012-4071 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 31 2012 12:00AM |
| Updated: | Aug 07 2012 12:22PM |
| Credit: | Stergios Kolios |
| Vulnerable: |
RSGallery2 RsGallery2 1.14.3 RSGallery2 RsGallery2 1.11.2 RSGallery2 RsGallery2 2.0.0b1 |
| Not Vulnerable: | |
Discussion
Joomla RSGallery2 Component HTML Injection and SQL Injection Vulnerabilities
RSGallery2 is prone to HTML injection and SQL injection vulnerabilities.
Exploiting these issues may allow an attacker to compromise the application, access or modify data, exploit vulnerabilities in the underlying database, execute HTML and script code in the context of the affected site, steal cookie-based authentication credentials, or control how the site is rendered to the user; other attacks are also possible.
Versions prior to RSGallery2 3.2.0 and 2.3.0 are vulnerable.
RSGallery2 is prone to HTML injection and SQL injection vulnerabilities.
Exploiting these issues may allow an attacker to compromise the application, access or modify data, exploit vulnerabilities in the underlying database, execute HTML and script code in the context of the affected site, steal cookie-based authentication credentials, or control how the site is rendered to the user; other attacks are also possible.
Versions prior to RSGallery2 3.2.0 and 2.3.0 are vulnerable.
Exploit / POC
Joomla RSGallery2 Component HTML Injection and SQL Injection Vulnerabilities
Attackers can exploit these issues using browser.
Attackers can exploit these issues using browser.
Solution / Fix
Joomla RSGallery2 Component HTML Injection and SQL Injection Vulnerabilities
Solution:
Vendor patch is available. Please see the references for more information.
Solution:
Vendor patch is available. Please see the references for more information.
References
Joomla RSGallery2 Component HTML Injection and SQL Injection Vulnerabilities
References:
References:
- RS Gallery2 Homepage (RS Gallery2)