vendor:
Joomla
by:
Egidio Romano
7,5
CVSS
HIGH
PHP Object Injection
502
CWE
Product Name: Joomla
Affected Version From: Version 3.0.3 and earlier 3.0.x versions, Version 2.5.9 and earlier 2.5.x versions
Affected Version To: Version 3.0.3 and earlier 3.0.x versions, Version 2.5.9 and earlier 2.5.x versions
Patch Exists: YES
Related CWE: CVE-2013-3242
CPE: a:joomla:joomla
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013
Joomla! <= 3.0.3 (remember.php) PHP Object Injection Vulnerability
User input passed through cookies is not properly sanitized before being used in an unserialize() call at line 45. This could be exploited to inject arbitrary PHP objects into the application scope. Successful exploitation of this vulnerability requires authentication because the attacker needs to know the 'hash string' used to read the cookie parameter at line 36.
Mitigation:
Upgrade to version 2.5.10, 3.0.4 or 3.1.0.