vendor:
Nice Ajax Poll
by:
Patrick de Brouwer - @knickz0r, NLSecurity - www.nlsecurity.org
9
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: Nice Ajax Poll
Affected Version From: 1.3.0
Affected Version To: 1.3.0
Patch Exists: NO
Related CWE: N/A
CPE: a:dmitry_kuprijanov:nice_ajax_poll
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Joomla!
2012
Joomla com_niceajaxpoll <= 1.3.0 SQL Injection Vulnerability
There is a SQL Injection vulnerability that can be called from within the website to perform the SQL Injection attack. The impact of this vulnerability should be rated as critical as it is possible to access the database and therefore retrieve user information such as usernames, passwords and other data. When abused, hackers could gain access to the administrative interface of Joomla.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in SQL queries.