Joomla RokModule Component Two SQL Injection Vulnerabilities

SECUNIA ADVISORY ID:
SA39255

VERIFY ADVISORY:
http://secunia.com/advisories/39255/

DESCRIPTION:
Two vulnerabilities have been discovered in the RokModule component
for Joomla, which can be exploited by malicious people to conduct SQL
injection attacks.

Input passed via the "module" and "moduleid" parameters to index.php
(when "option" is set to "com_rokmodule") is not properly sanitised
before being used in a SQL query. This can be exploited to manipulate
SQL queries by injecting arbitrary SQL code.

The vulnerabilities are confirmed in version 1.1. Other versions may
also be affected.

SOLUTION:
Edit the source code to ensure that input is properly sanitised.

PROVIDED AND/OR DISCOVERED BY:
AntiSecurity

ORIGINAL ADVISORY:
http://www.exploit-db.com/exploits/12148

RECENT ARTICLE

RECENT POST