Joomla com_jooproperty SQL injection && Cross site scripting Vulnerability
JooProperty is a real estate component developed for Joomla 1.7 and 2.5 with complex integrated booking features, price calculation for different seasons and comment and rating functions. The component is based on com-property for Joomla 1.5 of Fabio Ueltzinger and offers the possibility to import the database of com-property V3 and V4 to migrate your realty website to Joomla 2.5. All property relevant information like categories, locations, description, extras/amenities, season, price categories, prices and special fees can be translated. The vulnerable parameter is 'product_id' which is a querystring of type GET. Attack patterns for SQL injection and Cross Site Scripting are provided in the text.