Website Design Madison WI, Milwaukee, Madison Website CMS and SEO Services Madison, Milwaukee Wisconsin

Madison Website Design, Milwaukee, WI Web Site Design, CMS and SEO
Home » Support Blog » VirtueMart SQL Injection Vulnerability

VirtueMart SQL Injection Vulnerability

Edit Your Website - Content Management SystemIncrease Your Online Presence - Search Engine OptimizationDesign Your Website - Website DesignPrevent Website Headaches - Website Maintenance
Tools

Need Website Maintenance?

Divider
"I Want 24x7 Website Maintenance"
Get Quote

learn-about-website-video


If your website is using VirtueMart and you host with us, we will be upgrading your site with a patch:

VirtueMart "search_category" SQL Injection Vulnerability

Description
Andrea Fabrizi has discovered a vulnerability in VirtueMart, which can be exploited by malicious people to conduct SQL injection attacks.

Input passed via the "search_category" parameter to index.php (when "option" is set to "com_virtuemart" and "page" is set to "shop.browse") is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.

The vulnerability is confirmed in version 1.1.6. Other versions may also be affected.

Solution
Apply patch.
Further details available in Customer Area

Provided and/or discovered by
Andrea Fabrizi

Original Advisory
VirtueMart:
http://dev.virtuemart.com/projects/virtuemart/activity

This patch will take 1 Maintenance Block to install and test.

Thanks,
-Tony

Comments (0)Add Comment

Write comment
busy
Put Our Team
To Work For
You