vendor:
Phoca Gallery
by:
RoAd_KiLlEr
8,8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Phoca Gallery
Affected Version From: 2.7.3
Affected Version To: 2.7.3
Patch Exists: Yes
Related CWE: N/A
CPE: a:phoca:phoca_gallery
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Joomla!
2009
SQL-i Vulnerability
Phoca Gallery is a Joomla! gallery - image gallery for Joomla! CMS. It includes component, modules and plugins and allows users to display images or Youtube videos in many different styles. An attacker can exploit this vulnerability by sending a malicious SQL query to the vulnerable parameter 'Itemid' in the URL http://server/path/index.php?option=com_phocagallery&view=categories&Itemid=[SQL Injection].
Mitigation:
The vendor has released a patch to address this vulnerability. Users should upgrade to the latest version of Phoca Gallery.