Welcome, Guest
Please Login or Register.    Lost Password?

Security Vulnerability
(1 viewing) (1) Guest
Go to bottomPage: 1
TOPIC: Security Vulnerability
#2175
Security Vulnerability 5 Months ago Karma: 0
Dear moderators:

I recently purchased a subscription and almost pulled out my hair successfully getting the component and the modules to work properly. Then my site gets hacked; the index file is completely rewritten. Then I come across this little tidbit:

jVideoDirect Component for Joomla! "v" Parameter SQL Injection
08 February 2010

jVideoDirect is a component for the Joomla! content manager. The component is exposed to an SQL injection issue because it fails to sufficiently sanitize user-supplied data to the "v" parameter before using it in an SQL query. A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

Ref: www.securityfocus.com/bid/37990

10.6.51 - CVE: Not Available
Platform: Web Application - SQL Injection




I'm not saying that jvideodirect had anything to do with my current issue. However, do you plan on patching up your latest release?
KikiEss
(Basic Member)

Junior Boarder
Posts: 33
graphgraph
User Offline Click here to see the profile of this user
The administrator has disabled public write access.
 
#2177
Re: Security Vulnerability 5 Months ago Karma: 10
We have tested what they have reported, but nothing have happened.
JVD has blocked it and forward to "Private Video" page which request password.

Anyway, this lead us to enhance it, which has been done in the nightly build.

We can post it up as optional update.

regards

Tanny
cassie
jVideoDirect staff
Posts: 844
graph
User Offline Click here to see the profile of this user
Last Edit: 2010/02/24 10:46 By tanny.
The administrator has disabled public write access.
 
#2206
Re: Security Vulnerability 5 Months ago Karma: 0
Thank you. Just saw Tanny's post on the optional patch.
KikiEss
(Basic Member)

Junior Boarder
Posts: 33
graphgraph
User Offline Click here to see the profile of this user
The administrator has disabled public write access.
 
Go to topPage: 1
Moderators: cassie, tanny, ethan