Joomla Flash Magazine Deluxe Component "mag_id" SQL Injection

SECUNIA ADVISORY ID:
SA33646

VERIFY ADVISORY:
http://secunia.com/advisories/33646/

CRITICAL:
Moderately critical

IMPACT:
Manipulation of data

WHERE:
>From remote

SOFTWARE:
Flash Magazine Deluxe (component for Joomla!)
http://secunia.com/advisories/product/21140/

DESCRIPTION:
TurkGuvenligi has reported a vulnerability in the Flash Magazine
Deluxe component for Joomla!, which can be exploited by malicious
people to conduct SQL injection attacks.

Input passed via the "mag_id" parameter in index.php (when "option"
is set to "com_flashmagazinedeluxe") is not properly sanitised before
being used in SQL queries. This can be exploited to manipulate SQL
queries by injecting arbitrary SQL code.

SOLUTION:
Edit the source code to ensure that input is properly sanitised.

PROVIDED AND/OR DISCOVERED BY:
TurkGuvenligi

ORIGINAL ADVISORY:
http://milw0rm.com/exploits/7881

DOWNLOAD
JOOMLA!


Download Joomla!

Joomla! 4.x Thai Translation Language Packs

Joomla! 3.x Thai Translation Language Packs

OUR NETWORK


CMSPlugin.com
Joomla Extensions, Joomla Templates

Joomla!® User Group Thailand
Joomla!® User Group Thailand


Marvelic Engine Co., Ltd. รับพัฒนาเว็บไซต์ด้วย Joomla! , รับอบรม Joomla , ผู้เชี่ยวชาญ จูมล่า
รับทำเว็บ Joomla, อบรบ Joomla

Ribbon