Joomla version 2.5.4 appears to suffer from a remote SQL injection vulnerability.
984d04eda411c115a54fe7f6915c6bc8857118502a6bbd9afb1dde5320389cf4
[ TITLE ....... ][ Joomla 2.5.4 with components/extensions I found @ webs
[ DATE ........ ][ 07.04.2012
[ AUTOHR ...... ][ http://hauntit.blogspot.com
[ SOFT LINK ... ][ http://joomla.org
[ VERSION ..... ][ 2.5.4
[ TESTED ON ... ][ LAMP
[ ----------------------------------------------------------------------- [
[ 1. What is this?
[ 2. What is the type of vulnerability?
[ 3. Where is bug :)
[ 4. More...
[--------------------------------------------[
[ 1. What is this?
This is very nice CMS, You should try it! ;)
[--------------------------------------------[
[ 2. What is the type of vulnerability?
When admin add 'the same content' twicely, then he will see an error similar to this:
"Duplicate entry 'c9ujq(...)63rscpi5' for key 'PRIMARY' SQL=INSERT INTO `qcd3p_session` (`session_id`, `client_id`, `time`) VALUES ('c9u(...)i5', 1, '1338(...)88')"
So now 'attacker' can find out what is the prefix of Your Joomla installation.
In other way, this bug is available only from admin. ;)
[--------------------------------------------[
[ 3. Where is bug :)
http://joomla/administrator/index.php?option=com_installer&view=update&task=%2bunion%2bselect%2bnull--.ajax
[--------------------------------------------[
[ 4. More...
- http://www.joomla.org
- http://hauntit.blogspot.com
- http://www.google.com
- http://portswigger.net
* Why 'with friends' - because I added to my localhost Joomla installation so
many extensions (to tests;)), so vulnerable could be else part of CMS too (for example:
similar bug I found in latest VirtueMart 2.0.2. Check out at my blog. *
[
[--------------------------------------------[
[ All questions about new projects @ mail now :)
]
[ Best regards
[