Jojo cms x-Forwarded-For header SQL Injection Vulnerability
Release date:
Updated on:
Affected Systems:
Jojo CMS <1.2.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 59934
CVE (CAN) ID: CVE-2013-3081
Jojo CMS is SEO-friendly, scalable, and PHP-based CMS.
Earlier than Jojo CMS 1.2.2, plugins/jojo_core/classes/Jojo. the checkEmailFormat function in php has the SQL injection vulnerability. Remote attackers can execute arbitrary SQL commands by sending the X-Forwarded-For HTTP header to/articles/test.
<* Source: High-Tech Bridge SA (http://www.htbridge.ch /)
Link: http://xforce.iss.net/xforce/xfdb/84285
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Jojo CMS
--------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Https://github.com/JojoCMS/Jojo-CMS
This article permanently updates the link address: