Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Sql injection bugs in Joomla and Mambo Feb 04 2007 05:06PM
Omid (omid hackers ir)
Hi,

These bugs were published in full-disclosure about 2 weeks ago (CVE :
CVE-2007-0373, CVE-2007-0374 and CVE-2007-0375, CVE-2007-0387) .

In Mambo 4.6.1 and Joomla 1.0.11 (and 1.5 Beta) , the 'id' parameter can
cause sql injection when cancelling content editting . Other versions maybe
affected ...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus