vendor:
JINC (Joomla! Integrated Newsletters Component)
by:
Chip D3 Bi0s
N/A
CVSS
N/A
Blind SQL Injection
89
CWE
Product Name: JINC (Joomla! Integrated Newsletters Component)
Affected Version From: 0.2
Affected Version To: 0.2
Patch Exists: YES
Related CWE: N/A
CPE: a:lhacky:jinc:0.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
joomla component com_jinc (newsid) Blind SQL Injection Vulnerability
A Blind SQL Injection vulnerability exists in Joomla component com_jinc (newsid). An attacker can exploit this vulnerability to gain access to sensitive information from the application. The vulnerable code is located in the file index.php, where the variable newsid is not properly sanitized before being used in a SQL query. To exploit this vulnerability, an attacker must be registered in the website and send a malicious request to the application. The request should contain a malicious payload in the newsid parameter.
Mitigation:
Update to version 0.2.1