header-logo
Suggest Exploit
vendor:
Joomla!
by:
Not mentioned
5.5
CVSS
MEDIUM
Information Disclosure
200
CWE
Product Name: Joomla!
Affected Version From: Prior to Joomla! 1.5.22
Affected Version To: Joomla! 1.5.21
Patch Exists: YES
Related CWE: CVE-2011-4886
CPE: a:joomla:joomla:1.5.21
Metasploit:
Other Scripts:
Platforms Tested:
2011

Joomla! Information Disclosure Vulnerability

Joomla! is prone to an information-disclosure vulnerability due to an SQL error. Exploiting this issue can allow attackers to gain access to sensitive information contained in the application's database. Successful exploits may lead to other attacks.

Mitigation:

Upgrade to Joomla! 1.5.22 or later.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/44674/info

Joomla! is prone to an information-disclosure vulnerability due to an SQL error.

Exploiting this issue can allow attackers to gain access to sensitive information contained in the application's database. Successful exploits may lead to other attacks.

Versions prior to Joomla! 1.5.22 are vulnerable. 

http://yehg.net/lab/pr0js/advisories/joomla/core/1.5.21/sql_injection/sqli_(filter_order)_front.jpg
http://yehg.net/lab/pr0js/advisories/joomla/core/1.5.21/sql_injectio /sqli_%28filter_order_Dir%29_front.jpg
http://yehg.net/lab/pr0js/advisories/joomla/core/1.5.21/sql_injectio /sqli_%28filter_order_Dir%29_back.jpg