Joomla! Face Gallery SQL Injection and Arbitrary File Download Vulnerabilities
BID:70082
Info
Joomla! Face Gallery SQL Injection and Arbitrary File Download Vulnerabilities
| Bugtraq ID: | 70082 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2014 12:00AM |
| Updated: | Sep 22 2014 12:00AM |
| Credit: | Claudio Viviani |
| Vulnerable: |
apptha Face Gallery 1.0 |
| Not Vulnerable: | |
Discussion
Joomla! Face Gallery SQL Injection and Arbitrary File Download Vulnerabilities
Joomla is prone to an SQL-injection vulnerability and an arbitrary file-download vulnerability because it fails to sanitize user-supplied data.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database and to download arbitrary files from the Web server, obtain potentially sensitive information.
Face Gallery 1.0 is vulnerable; other versions may also be affected.
Joomla is prone to an SQL-injection vulnerability and an arbitrary file-download vulnerability because it fails to sanitize user-supplied data.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database and to download arbitrary files from the Web server, obtain potentially sensitive information.
Face Gallery 1.0 is vulnerable; other versions may also be affected.
Solution / Fix
Joomla! Face Gallery SQL Injection and Arbitrary File Download Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Joomla! Face Gallery SQL Injection and Arbitrary File Download Vulnerabilities
References:
References: