vendor:
Freestyle FAQ Lite
by:
Chip D3 Bi0s
N/A
CVSS
N/A
SQL Injection
89
CWE
Product Name: Freestyle FAQ Lite
Affected Version From: 1.3
Affected Version To: 1.3
Patch Exists: N/A
Related CWE: N/A
CPE: a:freestyle-joomla:freestyle_faq_lite
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Joomla
2010
Joomla Freestyle FAQ Lite Component 1.3 (faqid) SQL Injection
A vulnerability exists in Freestyle FAQ Lite Component 1.3 (faqid) which allows an attacker to inject arbitrary SQL commands via the faqid parameter in the URL. An attacker can exploit this vulnerability to gain access to sensitive information from the database.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in SQL queries.