Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

January 23rd, 2012, 09:38 GMT · By

BLOG

SQL Injection Flaw Found in Joomla ‘Com_Mobile’ and Other Components

SHARE:

Adjust text size:


Joomla administration panel Enlarge picture - Joomla administration panel
Researchers from the Vulnerability Lab found a high-risk SQL Injection vulnerability in Joomla’s com_mobile component.

The security flaw discovered in the popular content management system’s (CMS) component allows a remote attacker to inject his own SQL commands on the affected application’s database management system (DBMS).

If the weakness is successfully exploited, a hacker could compromise the DBMS, the website and the application.

Experts from the TheCyberNuxbie found the same flaw in other Joomla components such as com_full, com_car and com_sanpham. A number of zero-day LFI vulnerabilities were found in components such as com_boss, com_some, com_bulkequery and com_kp.

All the security holes were identified in the past few days, but for now there is no information provided for workarounds or patches.

Unfortunately, the ones that found them claim that even some government websites use these components, potentially exposing them to malicious operations.
FILED UNDER:
Joomla
SQL Injection
LFI

TELL US WHAT YOU THINK:

2,239 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


XSS Attacks Possible due to IE URI Encoding Flaw

Apache Tomcat Users Advised to Update to Avoid Hash DOS Attacks

Oracle Fixes 78 Flaws in January Critical Patch Update

Zero-Day Vulnerability Found in McAfee’s SaaS Products (Updated)

MyBB Users Exposed Due to Vulnerable Plugins

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM