vendor:
Tickets
by:
Chip D3 Bi0s
7,5
CVSS
HIGH
SQL injection
89
CWE
Product Name: Tickets
Affected Version From: 0.1
Affected Version To: 2.1
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Joomla, Mambo
2009
Joomla Component com_tickets (id) SQL-injection Vulnerability
A vulnerability exists in Joomla Component com_tickets (id) which allows an attacker to inject arbitrary SQL commands via the 'id' parameter. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. The vulnerability is confirmed in version 0.1 and 2.1. Demo Live Joomla and Mambo versions are also provided.
Mitigation:
Upgrade to the latest version of Joomla Component com_tickets.