Description
|
|
(#Several vulnerabilities were reported in third-party modules for Joomla:#- Fsave: local file disclosure via the "filename" parameter of the "plugins/content/fsave/download.php" script page#- Hotproperty: SQL injection via the "Itemid" parameter of the "index.php?option=com_hotproperty&task=asearch" web page#- Forum: injection SQL via the "catid" parameter of the "index.php?option=com_forum" web page##Proofs of concept are available.##An exploitation code is available for the vulnerability impacting the plugin Forum.)
|