DS-Syndicate Component - SQL Injection

For all Non-Joomla! security issues. ie 3pd Components etc.

Moderator: General Support Moderators

Forum rules
Locked
koaweb
Joomla! Apprentice
Joomla! Apprentice
Posts: 21
Joined: Sun Jul 01, 2007 8:28 am

DS-Syndicate Component - SQL Injection

Post by koaweb » Tue Oct 28, 2008 3:44 am

A vulnerability has been identified in DS-Syndicate (component for Joomla), which could be exploited by attackers to manipulate and inject SQL queries. This issue is caused by an input validation error when processing the "feed_id" parameter, which could be exploited by malicious people to conduct SQL injection attacks and gain knowledge of sensitive information.

Information from FrSiRT on 10-20-08
http://www.frsirt.com/english/advisories/2008/2859

Locked

Return to “3rd Party/Non Joomla! Security Issues”