Archive

Archive for the ‘Vulnerabilities’ Category

Joomla! Zoom Portfolio Component “id” SQL Injection

August 25th, 2010
Comments Off

Application: Joomla!
Affected Version: version 1.5 and other versions.
Vendor’s URL: Zoom Portfolio Component
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitised.

Content Management, SQL Injection

Joomla JGrid Component File Inclusion and SQL Injection

August 25th, 2010
Comments Off

Application: Joomla
Affected Version: Version 1.0 and other versions.
Vendor’s URL: JGrid Component
Bug Type: File Inclusion and SQL Injection
Risk Level: Critical

Solution:
Update to version 1.1.

Content Management, File Inclusion, SQL Injection

Free Simple CMS Remote File Inclusion

August 25th, 2010
Comments Off

Application: Free Simple CMS
Affected Version: version 1.0 and other versions.
Vendor’s URL: Free Simple CMS
Bug Type: File Inclusion
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly verified.

Content Management, File Inclusion

CMSQLite Arbitrary File Upload and Security Bypass

August 25th, 2010
Comments Off

Application: CMSQLite
Affected Version: version 1.3.1 and other versions.
Vendor’s URL: CMSQLite
Bug Type: File Upload and Security Bypass
Risk Level: Critical

Solution:
Restrict access to the “admin” directory (e.g. via a “.htaccess” file).

Access Bypass, Content Management, File Inclusion

Joomla onGallery Component “id” SQLi

August 25th, 2010
Comments Off

Application: Joomla
Affected Version: version 2.0.1 and other versions.
Vendor’s URL: onGallery Component
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitised.

Content Management, SQL Injection

CMS Source Multiple Vulnerabilities

August 25th, 2010
Comments Off

Application: CMS Source
Affected Version: version 3.0 and other versions.
Vendor’s URL: CMS Source
Bug Type: Cross Site Scripting and SQL Injection
Risk Level: Medium

Solution:
Edit the source code to ensure that input is properly sanitised and verified.

Content Management, Cross Site Scripting, SQL Injection

Pligg Multiple SQLi

August 25th, 2010
Comments Off

Application: Pligg
Affected Version: version 1.1.0 and other versions.
Vendor’s URL: Pligg
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Update to version 1.1.1.

Content Management, SQL Injection

Joomla! Teams Component “PlayerID” SQLi

August 25th, 2010
Comments Off

Application: Joomla!
Affected Version: Version 1 and other versions.
Vendor’s URL: Teams Component
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitised.

Content Management, SQL Injection

Joomla! Amblog Component “catid” and “articleid” SQLi

August 25th, 2010
Comments Off

Application: Joomla!
Affected Version: version 1.0 and other versions.
Vendor’s URL: Amblog Component
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitised.

Content Management, SQL Injection, Session Hijacking

Joomla! cgTestimonial Component Cross-Site Scripting and Arbitrary File Upload

August 25th, 2010
Comments Off

Application: Joomla!
Affected Version: version 1.0 and other versions.
Vendor’s URL: cgTestimonial Component
Bug Type: Cross Site Scripting and File Upload
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitised. Restrict access to the components/com_cgtestimonial/user_images directory (e.g. via .htaccess)

Content Management, Cross Site Scripting, File Inclusion

WordPress NextGEN Smooth Gallery Plugin “galleryID” SQLi

August 25th, 2010
Comments Off

Application: WordPress
Affected Version: version 1.2 and other versions.
Vendor’s URL: NextGEN Smooth Gallery Plugin
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitised.

Content Management, SQL Injection

Joomla! Spielothek Component Multiple SQLi

August 25th, 2010

Application: Joomla!
Affected Version: version 1.6.9 and other versions.
Vendor’s URL: Spielothek Component
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitised.

Content Management, SQL Injection

EasyManage CMS “id” Two SQL Injections

August 25th, 2010
Comments Off

Application: EasyManage CMS
Affected Version:
Vendor’s URL: EasyManage CMS
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Reportedly a patch has been released. Contact the vendor for further information.

Content Management, SQL Injection

Joomla! TTVideo Component “cid” SQLi

July 29th, 2010
Comments Off

Application: Joomla!
Affected Version: version 1.0 and other versions.
Vendor’s URL: TTVideo Component
Bug Type: SQL Injection
Risk Level: Critical

Solution:

Content Management, SQL Injection

Joomla! IT Armory Component Multiple SQLi

July 29th, 2010
Comments Off

Application: Joomla!
Affected Version: version 0.1.4 and other versions.
Vendor’s URL: IT Armory Component
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitised.

Content Management, SQL Injection

Joomla Frei-Chat Component One Script Insertion

July 29th, 2010
Comments Off

Application: Joomla
Affected Version: versions prior to 2.1.2.
Vendor’s URL: Frei-Chat Component
Bug Type: Cross Site Scripting
Risk Level: Medium

Solution:
Update to version 2.1.2.

Content Management, Cross Site Scripting

WordPress myLinksDump Plugin “url” SQLi

July 29th, 2010
Comments Off

Application: WordPress
Affected Version:
Vendor’s URL: myLinksDump Plugin
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitised.

Content Management, SQL Injection

Joomla InstantPhp Jobs Component “detailed_results” SQLi

July 29th, 2010
Comments Off

Application: Joomla
Affected Version: version 1.3.2 and other versions
Vendor’s URL: InstantPhp Jobs Component
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Update to version 1.3.3.

Content Management, SQL Injection

CMS Made Simple Download Manager Module Arbitrary File Upload

July 29th, 2010
Comments Off

Application: CMS Made Simple
Affected Version: version 1.4.1 and other versions.
Vendor’s URL: Download Manager Module
Bug Type: File Upload
Risk Level: Critical

Solution:
Restrict access to the “modules/DownloadManager/lib/simple-upload/example.php” script (e.g. via .htaccess)

Content Management, File Inclusion

Joomla AutarTimonial Component “limit” SQLi

July 29th, 2010
Comments Off

Application: Joomla
Affected Version: version 1.0.8 and other versions.
Vendor’s URL: AutarTimonial Component
Bug Type: SQL Injection
Risk Level: Critical

Solution:
Edit the source code to ensure that input is properly sanitised.

Content Management, SQL Injection