CVE-2011-4829 – Joomla! Component Barter Sites 1.3 - Multiple Vulnerabilities
https://notcve.org/view.php?id=CVE-2011-4829
SQL injection vulnerability in the com_listing component in Barter Sites component 1.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter to index.php. Vulnerabilidad de inyección SQL en el componente com_listing en el componente Barter Sites v1.3 para Joomla! permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro category_id en index.php • https://www.exploit-db.com/exploits/18046 http://docs.joomla.org/Vulnerable_Extensions_List#Barter_Sites_1.3 http://my.barter-sites.com/index.php?option=com_content&view=article&id=6&Itemid=25 http://www.exploit-db.com/exploits/18046 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2011-4830 – Joomla! Component Barter Sites 1.3 - Multiple Vulnerabilities
https://notcve.org/view.php?id=CVE-2011-4830
Multiple cross-site scripting (XSS) vulnerabilities in the com_listing component in Barter Sites component 1.3 for Joomla! allow remote authenticated users to inject arbitrary web script or HTML via the (1) listing_title, (2) description, (3) homeurl (aka Website Address), (4) paystring (aka Payment types accepted), (5) sell_price, (6) shipping_cost, and (7) quantity parameters to index.php. Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en el componente com_listing en el componente Barter Sites v1.3 para Joomla! permite a usuarios autenticados remotamente inyectar secuencias de comandos web o HTML a través de los parámetros (1) listing_title, (2) description, (3) homeurl (también conocido como Website Address), (4) paystring (también conocido como Payment types accepted), (5) sell_price, (6) shipping_cost, y (7) quantity en index.php • https://www.exploit-db.com/exploits/18046 http://docs.joomla.org/Vulnerable_Extensions_List#Barter_Sites_1.3 http://my.barter-sites.com/index.php?option=com_content&view=article&id=6&Itemid=25 http://www.exploit-db.com/exploits/18046 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •