vendor:
AWDwall-Joomla
by:
AntiSecurity
8,8
CVSS
HIGH
Local File Inclusion & SQL Injection
89, 79
CWE
Product Name: AWDwall-Joomla
Affected Version From: 1.5.4
Affected Version To: 1.5.4
Patch Exists: Yes
Related CWE: N/A
CPE: a:awdsolution:awdwall
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Joomla Component AWDwall-Joomla LFI & SQLi [cbuser] Vulnerability
A vulnerability in the Joomla Component AWDwall-Joomla allows an attacker to perform a Local File Inclusion (LFI) and a SQL Injection (SQLi) attack. The vulnerability exists in the com_awdwall version 1.5.4, which is vulnerable to an LFI attack when the ‘controller’ parameter is manipulated. Additionally, the ‘cbuser’ parameter is vulnerable to a SQLi attack when the ‘view’ parameter is set to ‘awdwall’ and the ‘Itemid’ parameter is set to ‘1’.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of the software.