Joomla! TPJobs Component “id_c[]” SQLi
Application: Joomla
Affected Version: versions prior to 1.1
Vendor’s URL: TPJobs Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Update to version 1.1.
Application: Joomla
Affected Version: versions prior to 1.1
Vendor’s URL: TPJobs Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Update to version 1.1.
Application: Xoops
Affected Version: version 2.4.2 and prior versions.
Vendor’s URL: Xoops
Bug Type: Cross Site Scripting and SQL Injection
Risk Level: Medium
Solution:
Update to version 2.4.3.
Application: Joomla
Affected Version: version 1.5
Vendor’s URL: iF Portfolio Nexus Component
Bug Type: File Inclusion
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly verified.
Application: Joomla!
Affected Version:
Vendor’s URL: BeeHeard Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Filter malicious characters and character sequences using a proxy.
Application: WordPress
Affected Version:
Vendor’s URL: Woopra Analytics Plugin
Bug Type: System Access
Risk Level: Critical
Solution:
Update to version 1.4.3.2.
Remove ofc_upload_image.php file from the Open Flash Chart directory.
Application: Joomla
Affected Version: version 1.0.0.1 and other versions.
Vendor’s URL: JEEMA Article Collection Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
Application: Joomla
Affected Version: version 1.0.0 and other versions.
Vendor’s URL: JoomPortfolio Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
Application: WP-Forum
Affected Version: versions 2.3 and 2.4 and other versions.
Vendor’s URL: WP-Forum
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
Application: Invision Power Board
Affected Version: version 2.3.6 and other versions.
Vendor’s URL: Invision Power Board
Bug Type: Script Insertion and SQL Injection
Risk Level: Medium
Solution:
Upgrade to version 3.0.5 or later.
Application: Joomla
Affected Version: version 1.0
Vendor’s URL: JPhoto Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Update to version 1.1 or later.
Application: Zen Cart
Affected Version: version 1.3.8a (full fileset 12112007) and other versions
Vendor’s URL: Zen Cart
Bug Type: File Inclusion
Risk Level: Critical
Solution:
The vendor recommends to delete the “extras” folder from the webroot.
Application: Wordpress
Affected Version: version 3.2.4 and other versions
Vendor’s URL: Google Analytics Plugin
Bug Type: Cross Site Scripting
Risk Level: Medium
Solution:
Update to version 3.2.5.
Application: Joomla
Affected Version: version 1.0 and others
Vendor’s URL: Joaktree Component
Bug Type: SQL Injection
Risk Level: High
Solution:
Edit the source code to ensure that input is properly sanitised.
Application: Joomla
Affected Version: version 1.0.4 and other versions
Vendor’s URL: LyftenBloggie Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
Application: Joomla
Affected Version: version 2.1.4 and other versions
Vendor’s URL: GCalendar Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
Application: Joomla
Affected Version: version 1.1
Vendor’s URL: iF Portfolio Nexus Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
Application: JoomClip
Affected Version:
Vendor’s URL: JoomClip
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Edit the source code to ensure that input is properly sanitised.
Filter malicious characters and character sequences in a proxy.
Application: XOOPS
Affected Version: prior to 2.4.1
Vendor’s URL: XOOPS Profile Activation
Bug Type: Security Bypass
Risk Level: Medium
Solution:
Update to version 2.4.1.
Application: WordPress
Affected Version: version 2.8.5
Vendor’s URL: WordPress
Bug Type: File Upload and Script Insertion
Risk Level: Medium
Solution:
Update to version 2.8.6.
Application: Joomla
Affected Version:
Vendor’s URL: Jumi Component
Bug Type: Access Bypass
Risk Level: Critical
Solution:
The vendor has released clean installation files.