Description
|
|
(#Several vulnerabilities were reported in third-party modules for Joomla:#- Nice Ajax: SQL injection via the "getpliseid" parameter of the "index.php?option=com_niceajaxpoll" web page#- Shape 5 MP3 Player: local file disclosure via the "fileurl" parameter of the "plugins/content/s5_media_player/helper.php" web page#- My Dyn Gallery: several SQL injections.###A proof of concept is available for Nice Ajax.##Exploitation codes are available for Shape 5 MP3 Player and My Dyn Gallery.)
|