vendor:
Gift Exchange
by:
Chip D3 Bi0s
N/A
CVSS
N/A
SQL Injection
89
CWE
Product Name: Gift Exchange
Affected Version From: 1.0beta
Affected Version To: 1.0beta
Patch Exists: NO
Related CWE: N/A
CPE: a:socialables_studios:gift_exchange:1.0beta
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
joomla component Gift Exchange com_giftexchange (pkg) Remote Sql Injection
A vulnerability exists in the Gift Exchange component of Joomla, version 1.0beta, which allows an attacker to inject arbitrary SQL commands via the 'pkg' parameter in the 'showcase' view. This can be exploited to gain access to sensitive information such as usernames and passwords.
Mitigation:
Input validation should be used to prevent SQL injection attacks.