I´m looking for buy the pro version but , and this?

Find out what does your audience think

I´m looking for buy the pro version but , and this?

New postby Brujo » Tue Nov 24, 2015 6:37 am

High-Tech Bridge Security Research Lab discovered vulnerability in Sexy Polling Joomla Extension, which can be exploited to perform SQL Injection attacks.

Advisory ID: HTB23193 Product: Sexy Polling Joomla Extension Vendor: 2GLux Vulnerable Version(s): 1.0.8 and probably prior Tested Version: 1.0.8 Advisory Publication: December 26, 2013 [without technical details] Vendor Notification: December 26, 2013 Vendor Patch: January 8, 2014 Public Disclosure: January 16, 2014 Vulnerability Type: SQL Injection [CWE-89] CVE Reference: CVE-2013-7219 Risk Level: High CVSSv2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) Solution Status: Fixed by Vendor Discovered and Provided: High-Tech Bridge Security Research Lab ( https://www.htbridge.com/advisory/ ) ———————————————————————— ———————– Advisory Details: High-Tech Bridge Security Research Lab discovered vulnerability in Sexy Polling Joomla Extension, which can be exploited to perform SQL Injection attacks.
1) SQL Injection in Sexy Polling Joomla Extension: CVE-2013-7219 The vulnerability exists due to insufficient validation of “answer_id[]” HTTP POST parameter passed to “/components/com_sexypolling/vote.php” script. A remote unauthenticated attacker can execute arbitrary SQL commands in application’s database. The following exploitation example is based on DNS Exfiltration technique and may be used if the database of the vulnerable application is hosted on a Windows system. The PoC will send a DNS request demanding IP addess for version() (or any other sensetive output from the database) subdomain of “.attacker.com” (a domain name, DNS server of which is controlled by the attacker):


Read more at: http://hashtec.org


Can u give secure about this is repair and your module its secure ?

thx for ur time
Brujo
 
Posts: 1
Joined: Tue Nov 24, 2015 6:31 am

Re: I´m looking for buy the pro version but , and this?

New postby Edvard » Tue Nov 24, 2015 9:44 am

Hi,

The issue have been already fixed. Current version is 2.1.1.

Thanks!
Regards,

Edvard Ananyan - 2GLux Team

Please post a review at the Joomla Extensions Directory. It is very important for us!
Edvard
Site Admin
 
Posts: 1836
Joined: Mon Jun 28, 2010 1:54 pm
Location: Yerevan, Armenia


Return to Sexy Polling

Who is online

Users browsing this forum: No registered users and 1 guest