|
|
|
|
| |
| Jom Comment, "an advanced AJAX based comment system for Joomla! CMS presents a slick finish to your website, feature-rich and compatible with your existing system, all packaged in an easy-to-use nifty component". A vulnerability in the way Jom Comment works allows remote attackers to cause the product to execute arbitrary SQL statements. |
| |
Credit:
The information has been provided by Ian E Green.
|
| |
Vulnerable Systems:
* Jom Comment version 2.0 Build 345 (released 2007-12-12)
Immune Systems:
* Jom Comment version 2.2
The Joomla! component Jom Comment is vulnerable to SQL injection because it fails to properly sanitize user-supplied input. An attacker can exploit this vulnerability using common SQL injection techniques to compromise data contained in the Joomla! / MySQL database. Data includes the username, password hash, and password salt of every application user including the site administrator.
|
|
|
|
|
|
|
|
|
|