Welcome, Guest
Username: Password: Remember me
  • Page:
  • 1
  • 2

TOPIC: Vulnerable for SQL Injection

Vulnerable for SQL Injection 7 years 1 month ago #4959

Is there an update available for JO Facebook Gallery since the vulnerable sql injection on this component?

vel.joomla.org/live-vel/1932-jo-facebook...ry-4-5-sql-injection
The administrator has disabled public write access.

Vulnerable for SQL Injection 7 years 1 month ago #4960

  • marijke
  • marijke's Avatar
  • OFFLINE
  • New Member
  • Posts: 4
  • Karma: 0
A client of ours has two sites with this extension on it, so I would like to know too if you are planning to update this extension because of the vulnerability, if not we have to look at other options. Please let us know your response to the VEL listing...
The administrator has disabled public write access.

Vulnerable for SQL Injection 7 years 1 month ago #4961

  • Super User
  • Super User's Avatar
  • OFFLINE
  • Administrator
  • Posts: 3519
  • Thank you received: 278
  • Karma: 65
Hello my Friend
Please help me uninstall old version before install new version and check it again. I think problem because in new version we have using ajax when load image and load direct from Facebook and not using database
Or can you send me joomla admin via contact form? So we can check it.
Best regards
Bach Pham
The administrator has disabled public write access.

Vulnerable for SQL Injection 7 years 1 month ago #4962

  • marijke
  • marijke's Avatar
  • OFFLINE
  • New Member
  • Posts: 4
  • Karma: 0
Which version is Jo facebook gallery? On the joomla extensions directory it says that the component is version 4.5: extensions.joomla.org/profile/extension/...jo-facebook-gallery/ the one that is vulnerable... Is there a newer version?
The administrator has disabled public write access.

Vulnerable for SQL Injection 7 years 1 month ago #4963

  • Super User
  • Super User's Avatar
  • OFFLINE
  • Administrator
  • Posts: 3519
  • Thank you received: 278
  • Karma: 65
Hello Marijke
Version 4.5 is new version and problem because in new version we have using ajax when load image and load direct from Facebook and not using database and i think problem because the user have install upgrade new version (not uninstall old version before install new version)
So please help me unistall old version before install new version
Best regards
Bach Pham
The administrator has disabled public write access.

Vulnerable for SQL Injection 7 years 1 month ago #4964

  • marijke
  • marijke's Avatar
  • OFFLINE
  • New Member
  • Posts: 4
  • Karma: 0
The administrator has disabled public write access.
  • Page:
  • 1
  • 2
Time to create page: 0.147 seconds