vendor:
Easy Youtube Gallery
by:
Persian Hack Team
9
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Easy Youtube Gallery
Affected Version From: 1.0.2
Affected Version To: 1.0.2
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2016
Joomla Easy Youtube Gallery 1.0.2 SQL Injection Vulnerability
Joomla Easy Youtube Gallery 1.0.2 is vulnerable to SQL injection. An attacker can inject malicious SQL code into the 'mycategory' parameter of the 'com_easy_youtube_gallery' component. This can be exploited to gain access to the underlying database and potentially gain access to sensitive information.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in SQL queries.