CVE-2010-4902 Information

Description

Multiple SQL injection vulnerabilities in the Clantools (com_clantools) component 1.2.3 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) squad or (2) showgame parameter to index.php.

Reference

http://packetstormsecurity.org/1009-exploits/joomlaclantools-sql.txt http://secunia.com/advisories/41322 http://securityreason.com/securityalert/8440 http://www.exploit-db.com/exploits/14902 http://www.osvdb.org/67827 http://www.securityfocus.com/bid/42986

Share on: