foobla RSS Feed Creator for Joomla "id" SQL Injection
Description:
Chip d3 Bi0s has reported a vulnerability in foobla RSS Feed Creator for Joomla, which can be exploited by malicious people to conduct SQL injection attacks.
Input passed via the "id" parameter to index.php (if "option" is set to "com_jlord_rss" and "task" to "feed") is not properly sanitised before being used in an SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
Source: http://secunia.com/advisories/36748/
Solution: upgrade to latest version (1.5.1.1_build20090922)
See how to get newer version here.






Are you tired of spam on your Joomla site? Do you want a restricted registration/access solution? If so then this Joomla extensions is for you! Click here to see the features list, screenshots, and demo.
Have you ever used Uservoice? Perhaps, you like its useful features. However, whether you want or not, you have to pay monthly fee to use it. Would you like to have something that is similar to Uservoice on Joomla with unlimited features and no monthly fee?
