Joomla com_sectionex v2.5.96 SQL Injection vulnerabilities

2013-08-05 Thread Matias Fontanini
- Affected versions: version 2.5.96 is vulnerable. Other versions might be affected as well. - Author: Matias Fontanini == Vulnerabilities == When using the "category" view, the component does not correctly sanitize the "filter_order" and "filter_order_Dir" p

PHPFox v3.6.0 (build3) Multiple SQL Injection vulnerabilities

2013-08-07 Thread Matias Fontanini
vulnerable. Other versions might be affected as well. - Vulnerability discovered by: Matias Fontanini == Vulnerabilities == When performing POST requests to /user/browse/view_/, the "search[gender]" and "search[sort_by]" parameters are not correctly sanitized before being used to c

Joomla! redSHOP component v1.2 SQL Injection

2013-08-08 Thread Matias Fontanini
: version 1.2 is vulnerable. Other versions might be affected as well. - Vulnerability discovered by: Matias Fontanini == Vulnerability == When using the "addtocompare" task, the component does not correctly sanitize the "pid" parameter before using it to construct SQL queries, mak

Joomla! VirtueMart component <= 2.0.22a - SQL Injection

2013-08-22 Thread Matias Fontanini
and 2.0.22a are vulnerable. - Vulnerability discovered by: Matias Fontanini == Vulnerability == The vulnerability is located in the "user" controller, "removeAddressST" task. The "virtuemart_userinfo_id" parameter is not properly sanitized before being used in the "D

Joomla! JomSocial component < 3.1.0.1 - Remote code execution

2014-01-31 Thread Matias Fontanini
.6 and < 3.1.0.1 are vulnerable. - Vulnerability discovered by: Matias Fontanini and Gaston Traberg == Vulnerability == The vulnerability is located in the "photos" controller, "ajaxUploadAvatar" task. The parameters parsed by the "Azrul" plugin are not properly sanit