Description
SQL injection vulnerability in the AWDwall (com_awdwall) component before 1.5.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cbuser parameter in an awdwall action to index.php.
Affected products
References
- MISChttp://www.securityfocus.com/bid/38194
- VENDOR_ADVISORYhttp://secunia.com/advisories/39553
- MISChttp://www.awdwall.com/index.php/awdwall-updates-logs-
- EXPLOIThttp://packetstormsecurity.org/1004-exploits/joomlaawdwall-lfisql.txt
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/57694
- EXPLOIThttp://www.exploit-db.com/exploits/12113
- MISChttp://www.osvdb.org/63942