vendor:
Camelcitydb2
by:
H!tm@N
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Camelcitydb2
Affected Version From: 2.2
Affected Version To: 2.2
Patch Exists: YES
Related CWE: N/A
CPE: a:joomla:joomla
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Joomla Component Camelcitydb2 SQL Injection Vulnerability
An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable application. The attacker can inject arbitrary SQL code in the vulnerable parameter 'id' of the 'index.php' script. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. An example of a malicious request is '/index.php?option=com_camelcitydb2&id=-3+union+select+1,2,concat(username,char(58),password)KHG,4,5,6,7,8,9,10,11+from+jos_users--&view=detail&Itemid=15'
Mitigation:
The vendor has released an update to address this vulnerability. Users are advised to update to the latest version of the application.