1 results (0.004 seconds)

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 2

SQL injection vulnerability in the updateOnePage function in components/com_bfsurvey_pro/controller.php in BF Survey Pro Free (com_bfsurvey_profree) 1.2.4, and other versions before 1.2.6, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the table parameter in an updateOnePage action to index.php. Vulnerabilidad de inyección SQL en la función updateOnePage de components/com_bfsurvey_pro/controller.php del componente Joomla! BF Survey Pro Free (com_bfsurvey_profree) v1.2.4, y otras versiones anteriores a la v1.2.6. Permite a usuarios remotos ejecutar comandos SQL de su elección a través del parámetro "table" (tabla) de una acción updateOnePage de index.php. • https://www.exploit-db.com/exploits/9601 http://osvdb.org/57883 http://secunia.com/advisories/36657 http://www.exploit-db.com/exploits/9601 http://www.tamlyncreative.com.au/software/forum/index.php?topic=357.msg1334#msg1334 http://www.vupen.com/english/advisories/2009/2609 https://exchange.xforce.ibmcloud.com/vulnerabilities/53107 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •