The Laboratory Researcher (Nafsh) Ehram Shahmohamadi (sec-lab.ir) discovered a SQL Injection Vulnerability in the com_fireboard module of the joomla CMS.
Credit:
The information has been provided by Nafsh - Ehram Shahmohamadi.
A SQL Injection vulnerability is detected in the com_fireboard module of the joomla Content Management System. Remote attackers & low privileged user accounts can execute/inject own sql commands to compromise the application dbms. The vulnerability is located in the com_fireboard module with the bound vulnerable func fb_ parameter. Successful exploitation of the vulnerability result in dbms (Server) or application (Web) compromise.
Proof of Concept:
The sql injection vulnerability can be exploited by remote attackers without user inter action & with low privileged user account. For demonstration or reproduce ...