vendor:
com_awesom
by:
S@BUN
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: com_awesom
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2008
joomla SQL Injection(com_awesom)
The Joomla component com_awesom is vulnerable to SQL Injection. An attacker can exploit this vulnerability by injecting malicious SQL queries into the 'listid' parameter of the 'viewlist' task in the 'index.php' file. This allows the attacker to retrieve sensitive information from the database, such as usernames and passwords.
Mitigation:
To mitigate this vulnerability, it is recommended to update the com_awesom component to the latest version, or apply any patches or fixes provided by the vendor.