PT-2010-5520 · Joomla · Jextensions Je Auto
Drosophila
+1
·
Publicado
2010-12-09
·
Atualizado
2010-12-10
·
CVE-2010-4517
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
JExtensions JE Auto (com jeauto) component version 1.0 for Joomla!
Description
The issue allows remote attackers to execute arbitrary SQL commands when magic quotes gpc is disabled. This is achieved by exploiting the
char parameter in an item action to "index.php".Recommendations
For version 1.0, consider disabling the component until a patch is available, or ensure that magic quotes gpc is enabled to mitigate the risk of SQL injection attacks.
Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jextensions Je Auto