SQL Injection Weaknesses Found in Mambo, Joomla
Submitted by srlinuxx on Mon, 07/03/2006 - 08:14.
Potentially serious security flaws have been found in existing versions of the Mambo and Joomla content management systems, and developers of the two projects are advising users to install upgrades or security patches as soon as possible. Both programs are vulnerable to SQL injection attacks, which allow remote attackers to execute commands on the web server in by typing SQL code into form fields. Joomla is a fork of Mambo, with both programs derived from the same code base.
The Internet Storm Center said it is receiving reports that older versions of Mambo are being actively targeted and exploited using unpatched vulnerabilities.


Recent comments
5 hours 24 min ago
6 hours 15 min ago
6 hours 42 min ago
14 hours 54 min ago
15 hours 45 min ago
20 hours 52 min ago
21 hours 15 sec ago
21 hours 3 min ago