2 results (0.003 seconds)

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

A certain interface in the iCRM Basic (com_icrmbasic) component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Ciertas interfaces en el componente iCRM Basic (com_icrmbasic) v1.4.2.31 para Joomla! no requiere autenticación administrativa, lo que tiene un impacto y vectores de ataque no especificados. • http://secunia.com/advisories/36892 http://www.osvdb.org/58382 http://www.securityfocus.com/bid/36533 • CWE-287: Improper Authentication •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

SQL injection vulnerability in the iCRM Basic (com_icrmbasic) component 1.4.2.31 for Joomla! allows remote attackers to execute arbitrary SQL commands via the p3 parameter to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Vulnerabilidad de inyección SQL en el componente iCRM Basic (com_icrmbasic) v1.4.2.31 para Joomla! permite a los atacantes remotos ejecutar comandos SQL a través del parámetro p3 en index.php. • http://osvdb.org/58381 http://secunia.com/advisories/36892 http://www.securityfocus.com/bid/36533 https://exchange.xforce.ibmcloud.com/vulnerabilities/53493 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •