Joomla Flash Magazine Deluxe Component "mag_id" SQL Injection

SECUNIA ADVISORY ID:
SA33646

VERIFY ADVISORY:
http://secunia.com/advisories/33646/

CRITICAL:
Moderately critical

IMPACT:
Manipulation of data

WHERE:
>From remote

SOFTWARE:
Flash Magazine Deluxe (component for Joomla!)
http://secunia.com/advisories/product/21140/

DESCRIPTION:
TurkGuvenligi has reported a vulnerability in the Flash Magazine
Deluxe component for Joomla!, which can be exploited by malicious
people to conduct SQL injection attacks.

Input passed via the "mag_id" parameter in index.php (when "option"
is set to "com_flashmagazinedeluxe") is not properly sanitised before
being used in SQL queries. This can be exploited to manipulate SQL
queries by injecting arbitrary SQL code.

SOLUTION:
Edit the source code to ensure that input is properly sanitised.

PROVIDED AND/OR DISCOVERED BY:
TurkGuvenligi

ORIGINAL ADVISORY:
http://milw0rm.com/exploits/7881