Archive

Archive for January, 2010

LightOpenCMS “cwd” File Inclusion

January 27th, 2010
Comments Off

Application: LightOpenCMS
Affected Version: version 0.1 and other versions
Vendor’s URL: LightOpenCMS
Bug Type: File Inclusion
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly verified.
Set “register_globals” to “Off”.

Content Management, File Inclusion

Joomla! Component Ozio Gallery “writeToFile.php” File Manipulation

January 27th, 2010
Comments Off

Application: Joomla!
Affected Version: versions prior to 2.3.
Vendor’s URL: Ozio Gallery
Bug Type: File Manipulation
Risk Level: Critical

Solution:
Update to version 2.3.

http://www.joomla.it/download/oziogallery.html

Content Management

Joomla JBDiary Component Multiple SQLi

January 27th, 2010
Comments Off

Application: Joomla
Affected Version: version 1.6 and other versions.
Vendor’s URL: JBDiary Component
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitised.

Content Management, SQL Injection

Joomla Document Seller for Docman Component “id” SQLi

January 27th, 2010
Comments Off

Application: Joomla
Affected Version: version 2.1
Vendor’s URL: Document Seller for Docman Component
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitised.

Content Management, SQL Injection

Joomla jEmbed-Embed Anything Component “catid” SQLi

January 27th, 2010
Comments Off

Application: Joomla
Affected Version:
Vendor’s URL: jEmbed-Embed Anything Component
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitised.

Content Management, SQL Injection

Joomla! TPJobs Component “id_c[]” SQLi

January 27th, 2010
Comments Off

Application: Joomla
Affected Version: versions prior to 1.1
Vendor’s URL: TPJobs Component
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Update to version 1.1.

Content Management, SQL Injection

Xoops XSS and SQLi

January 27th, 2010
Comments Off

Application: Xoops
Affected Version: version 2.4.2 and prior versions.
Vendor’s URL: Xoops
Bug Type: Cross Site Scripting and SQL Injection
Risk Level: Medium

Solution:
Update to version 2.4.3.

Content Management, Cross Site Scripting, SQL Injection

Joomla iF Portfolio Nexus Component “controller” File Inclusion

January 27th, 2010
Comments Off

Application: Joomla
Affected Version: version 1.5
Vendor’s URL: iF Portfolio Nexus Component
Bug Type: File Inclusion
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly verified.

Content Management, File Inclusion

Joomla! BeeHeard Component “category_id” SQLi

January 27th, 2010
Comments Off

Application: Joomla!
Affected Version:
Vendor’s URL: BeeHeard Component
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Filter malicious characters and character sequences using a proxy.

Content Management, SQL Injection