Joomla Component com_datsogallery 1.6 Blind SQL Injection Exploit

OSVDB-ID: 44969 - http://osvdb.org/show/osvdb/44969

Description
<em style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-5208" target="_blank">CVE</a>)</em> : SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.

Classification
Location: Remote / Network Access
Attack Type: Information Disclosure, Input Manipulation
Impact: Loss of Confidentiality, Loss of Integrity
Exploit: Exploit Public
Disclosure: Uncoordinated Disclosure
OSVDB: Web Related

Products
Unknown or Incomplete

[Via - http://www.exploit-db.com/exploits/5583/]

0 Comment:

Posta un commento