Keyword

SQL INJECTIONS? Said my hosting Site

  • ricardo
  • ricardo's Avatar Topic Author
  • Offline
  • New Member
More
12 years 2 weeks ago #103403 by ricardo
SQL INJECTIONS? Said my hosting Site was created by ricardo
hello to the community, and the admins hope you can help me in this issuis.

the thing is that my hosting provider open me a ticket saiyng that i need to delete com_k2 due a vulnerability they send me this.

"Possible vulnerability: K2 Component 'category' Parameter SQL Injection Vulnerability
Versions affected: JoomlaWorks K2 1.0.1 beta
Detail: The K2 component for Joomla! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
More info: www.securityfocus.com/bid/35517/"

now very well, the version affected is 1.0.1 beta and the version that i have is 2.5.4 , so tell me if im wrong or not, but should i be worried?

Please Log in or Create an account to join the conversation.

More
12 years 2 weeks ago #103404 by Lefteris
Replied by Lefteris on topic Re: SQL INJECTIONS? Said my hosting Site
Hi. You are not affected since you have not the beta version mentioned there. Also always try to update K2 to it's latest stable version ( 2.5.7 currently ).

JoomlaWorks Support Team
---
Please search the forum before posting a new topic :)

Please Log in or Create an account to join the conversation.


Powered by Kunena Forum