vendor:
Joomla!
by:
M4dhead
7.5
CVSS
HIGH
SQL-Injection
89
CWE
Product Name: Joomla!
Affected Version From: Joomla <= 1.0.15
Affected Version To: Joomla <= 1.0.15
Patch Exists: NO
Related CWE:
CPE: a:joomla:joomla!::
Platforms Tested:
Joomla <=1.0.15 Component com_pms <=2.0.4 (Ignore-List) SQL-Injection Vuln
This exploit targets a vulnerability in the com_pms component of Joomla versions <= 1.0.15. The vulnerability allows an attacker to perform SQL injection attacks. The exploit requires a valid account on the target Joomla site with Community Builder Suite 1.1.0 installed. The attacker needs to copy the cookie information of a logged-in user and modify the User-Agent header of the POST request to match the browser used to log in. The exploit can be executed by running the provided script. If successful, the attacker can access the ignore list of the target site and view usernames and passwords.
Mitigation:
To mitigate this vulnerability, it is recommended to update Joomla to a version higher than 1.0.15 and ensure that the magic_quotes_gpc setting is enabled. Additionally, it is advised to regularly monitor and patch any known vulnerabilities in Joomla components.