vendor:
RSfiles
by:
ByEge
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: RSfiles
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2013
Joomla Component RSfiles <= (cid) SQL injection Vulnerability
The Joomla component RSfiles is vulnerable to SQL injection. By manipulating the 'cid' parameter in the URL, an attacker can execute arbitrary SQL queries.
Mitigation:
Update to the latest version of the RSfiles component or apply a patch provided by the vendor.