www.mamboteam.com
Jx Development
Home arrow Support Forum
Thursday, 11 March 2010
 
 
Main Menu
Home
FAQs
Portfolio
File Archive
Bug Reports
Support Forum
Development Update
Work in Progress
Web Links
Contact Me
Component Demos
Jobline Demo
Mamblog Demo
Jambook Demo
Login Form





Lost Password?
No account yet? Register
Who's Online
We have 17 guests online
Newsletter

Subscribe to our newsletter.






Donate
If you use and like my scripts, and would like further developments, please consider donating a few bucks.

External links
www.ledutveckling.com - The Yard - Utvecklaren - Rollspel.nu - Spelwebben - Gardener's Game Garage - My Pet Peeves - PSPnuts

Interesting Sites
Joomla!
Joomlahut
Netshine Joomla Tutorial
JX extensions on JED
Support Forum
Welcome, Guest
Please Login or Register.    Lost Password?
SQL Injection (1 viewing) (1) Guest
Go to bottom Post Reply Favoured: 0
TOPIC: SQL Injection
#5845
joeblack_8 (User)
Fresh Boarder
Posts: 2
graphgraph
User Offline Click here to see the profile of this user
SQL Injection 3 Months ago Karma: 0  
hii i have found this in milw0rm.com http://www.milw0rm.com/exploits/9187
this bug can cause the hack of ur site throw a blind sql injection
can any one till me how risky this bug ?
is it safe to use this component ??
thax
 
Report to moderator   Logged Logged  
  The administrator has disabled public write access.
#9091
alaoa (User)
Fresh Boarder
Posts: 5
graphgraph
User Offline Click here to see the profile of this user
Re:SQL Injection 4 Weeks ago Karma: 0  
Any SQL injection is a big risk. I think the developer took a hiatus because of all the negative posting on joomla. And frankly i don't blame him. He crated something for free and provided free support from what it looks like and still he gets people bitching at him. I checked out the code and you have to clean a couple of the vars and you will be good to go.

In the Jobline.php change the itemId var
Code:

$id = intval(mosGetParam( $_REQUEST ,'id', '' )); $Itemid = intval(mosGetParam( $_REQUEST ,'Itemid', '' ));
If you force them to ints no one can try malicious code in the urls
 
Report to moderator   Logged Logged  
  The administrator has disabled public write access.
#9093
olle (Admin)
Admin
Posts: 1031
graph
User Online Now Click here to see the profile of this user
Re:SQL Injection 3 Weeks, 6 Days ago Karma: 17  
Thanks. This has already been fixed for v1.2, but I should probably get a patch released for the current version as well.
 
Report to moderator   Logged Logged  
 
Olle Johansson
  The administrator has disabled public write access.
Go to top Post Reply
Powered by FireBoardget the latest posts directly to your desktop
Advertisement
Polls
Is Joomla 1.0 support needed in future releases of our extensions?
 
Latest News
Most Read
Latest Commented
Bug Reporting (1 comments)
Mamblog - User blog component (61 comments)
The road to Jobline v1.2 (5 comments)
Export vBulletin users to Mambo (6 comments)
Jobline Documentation (4 comments)
Latest Posts

More...
 
Top! Top!