vendor:
QuickFAQ
by:
RoAd_KiLlEr
8,8
CVSS
HIGH
BSQL-i Vulnerability
89
CWE
Product Name: QuickFAQ
Affected Version From: 1.0.3
Affected Version To: 1.0.3
Patch Exists: YES
Related CWE: N/A
CPE: a:schlu.net:quickfaq:1.0.3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2/SP3
2011
Joomla Component (com_quickfaq) BSQL-i Vulnerability
QuickFAQ is vulnerable to Blind SQL Injection. This vulnerability allows an attacker to execute arbitrary SQL commands on the vulnerable system. The vulnerability is located in the 'cid' parameter of the 'category' value of the 'view' parameter when making a GET request to the vulnerable application. An attacker can inject malicious SQL commands to manipulate the content of the database.
Mitigation:
Upgrade to the latest version of QuickFAQ.