Joomla! All Video Share Component "avssearch" SQL Injection Vulnerability

SECUNIA ADVISORY ID:
SA55888

VERIFY ADVISORY:
Secunia.com
http://secunia.com/advisories/55888/
Customer Area (Credentials Required)
https://ca.secunia.com/?page=viewadvisory&vuln_id=55888

RELEASE DATE:
2013-11-29
DESCRIPTION:
Compass Security has discovered a vulnerability in the All Video
Share component for Joomla!, which can be exploited by malicious
people to conduct SQL injection attacks.

Input passed via the "avssearch" parameter to index.php (when
"option" is set to "com_allvideoshare" and "view" is set to "search")
is not properly sanitised before being used in a SQL query. This can
be exploited to manipulate SQL queries by injecting arbitrary SQL
code.

The vulnerability is confirmed in version 2.0.0. Other versions may
also be affected.

SOLUTION:
Update to version 2.1.0.

PROVIDED AND/OR DISCOVERED BY:
Stefan Horlacher, Compass Security

ORIGINAL ADVISORY:
CSNC-2013-012:
http://www.csnc.ch/misc/files/advisories/COMPASS-2013-012_All_Video_Share_SQL_Injection_Vulnerability.txt

RECENT ARTICLE

RECENT POST