PT-2009-6170 · Joomla · Com Ninjacentral

Chip D3 Bi0S

·

Published

2009-11-18

·

Updated

2017-09-19

·

CVE-2009-3964

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions com ninjacentral version 1.1.0
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved by exploiting the testimID parameter in a display action to "index.php".
Recommendations For version 1.1.0, update to a newer version that contains a fix for this issue. As a temporary workaround, consider restricting access to the testimID parameter in the affected API endpoint until a patch is available.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-3964

Affected Products

Com Ninjacentral