vendor:
Joomla
by:
B-HUNT3|2
5,5
CVSS
MEDIUM
SQL Injection
89
CWE
Product Name: Joomla
Affected Version From: 1.5
Affected Version To: 1.5
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Demo Site and Official Site
2010
Joomla (com_ContentBlogList) SQL Injection Vulnerabilities
Multiple input vars are vulnerable to SQL code injection. A proof of concept is provided which shows that an attacker can execute arbitrary SQL queries by exploiting the vulnerable parameters. The vulnerable parameters are 'searchword', 'id', 'section_id' and more.
Mitigation:
Upgrade to the latest version of Joomla.