vendor:
Gnosis
by:
Ihsan Sencan
8,8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Gnosis
Affected Version From: 1.1.2
Affected Version To: 1.1.2
Patch Exists: YES
Related CWE: N/A
CPE: a:hypermodern:gnosis:1.1.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Win7 x64, Kali Linux x64
2017
Joomla! Component Gnosis v1.1.2 – SQL Injection
A SQL injection vulnerability exists in Joomla! Component Gnosis v1.1.2. An attacker can send a malicious SQL query to the vulnerable application in order to gain access to unauthorized information. The vulnerable parameter is the 'id' parameter which can be found in the URL when viewing a tag. An attacker can inject malicious SQL code into the 'id' parameter in order to execute arbitrary SQL commands.
Mitigation:
Input validation should be used to prevent SQL injection attacks. All user-supplied input should be validated and filtered before being used in an SQL query.