7.5
CVSSv2

CVE-2010-4902

Published: 08/10/2011 Updated: 14/02/2012
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in the Clantools (com_clantools) component 1.2.3 for Joomla! allow remote malicious users to execute arbitrary SQL commands via the (1) squad or (2) showgame parameter to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

joomla-clantools clantools com_clantools

Exploits

# Exploit Title: Joomla Component Clantools version 15 Blind SQL Injection Vulnerability # Date: 05092010 # Author: Stephan Sattler // Solidmedia # Software Link: joomla-clantoolsde/downloads/doc_download/26-clantools-v15-fuer-joomla-15xhtml # Version: 15 [ Vulnerability 1 ] wwwsitecom/joomlapath/indexphp?option=com_clanto ...
# Exploit Title: Joomla Component Clantools version 123 Multiple Blind SQL Injection Vulnerability # Date: 05092010 # Author: Stephan Sattler // Solidmedia # Software Link: wwwjoomla-clantoolsde/downloads/doc_download/7-clantools-123html # Version: 123 [ Vulnerability 1 ] wwwsitecom/joomlapath/indexphp?option=com_clanto ...