vendor:
com_actualite
by:
Stack-Terrorist
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: com_actualite
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2008
Joomla Component com_actualite SQL Injection
SQL injection vulnerability in the com_actualite component in Joomla allows remote attackers to execute arbitrary SQL commands via the edit task in the id parameter, as demonstrated by injecting a UNION SELECT statement to retrieve usernames and passwords from the jos_users table.
Mitigation:
Update to a fixed version of the component or apply a patch provided by the vendor.