SQL Injection Vulnerabilities in BSQ Sitestats Component for Joomla
CVE-2006-7123
Currently unrated
Summary
The BSQ Sitestats component for Joomla is susceptible to multiple SQL injection vulnerabilities. These flaws allow attackers to execute arbitrary SQL commands through unspecified parameters during the import of the 'ip-to-country.csv' file and via HTTP headers such as HTTP Referer, HTTP User Agent, and HTTP Accept Language sent to the 'bsqtemplateinc.php' file. Exploiting these vulnerabilities can lead to unauthorized access to sensitive database information and could facilitate further attacks on the Joomla installation.
References
Timeline
Vulnerability published
Vulnerability Reserved