Autore Topic: Joomla Component Xmap v. 1.2.11 SQL Injection Vulnerability  (Letto 2084 volte)

Offline jeckodevelopment

  • Administrator
  • Instancabile
  • *****
  • Post: 5659
  • Sesso: Maschio
    • Mostra profilo
Joomla Component Xmap version 1.2.11 SQL Injection Vulnerability

Codice: [Seleziona]
# Exploit Title: Xmap 1.2.11 Joomla Component Blind SQL Injection
# Date: 12 July 2011
# Author: jdc
# Software Link:
http://joomlacode.org/gf/project/xmap/frs/?action=FrsReleaseBrowse&frs_package_id=3882
# Version: 1.2.11
# Fixed In: 1.2.12
 
Versions prior to 1.2.12 suffer from a blind sql injection in the "view"
parameter, depending on Xmap's internal cache settings.
 
POSTDATA: option=com_xmap&tmpl=component&Itemid=999&view=[SQL]
 
1.2.12 has been patched. Older versions with cache=off cannot be
exploited in this fashion.

Lo sviluppatore ha rilasciato il 14 luglio una nuova versione del componente che corregge la vulnerabilitÓ, si consiglia pertanto di procedere immediatamente con l'aggiornamento alla versione 1.2.12.

http://extensions.joomla.org/extensions/site-management/site-map/3066/details

 

Host

Torna su