PT-2010-5520 · Joomla · Jextensions Je Auto
Drosophila
+1
·
Published
2010-12-09
·
Updated
2010-12-10
·
CVE-2010-4517
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
JExtensions JE Auto (com jeauto) component version 1.0 for Joomla!
Description
The issue allows remote attackers to execute arbitrary SQL commands when magic quotes gpc is disabled. This is achieved by exploiting the
char parameter in an item action to "index.php".Recommendations
For version 1.0, consider disabling the component until a patch is available, or ensure that magic quotes gpc is enabled to mitigate the risk of SQL injection attacks.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jextensions Je Auto