Skip to main content

Joomla! Multiple Vulnerabilities

Last Update Date: 8 Mar 2012 12:15 Release Date: 8 Mar 2012 4472 Views

RISK: Medium Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

Two vulnerabilities have been identified in Joomla!, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.

  1. Certain input passed to the Highlight plugin is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
  2. Certain input passed to the Redirect plugin is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.

Impact

  • Cross-Site Scripting

System / Technologies affected

  • Joomla! 2.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to version 2.5.2.

Vulnerability Identifier


Source


Related Link