SQL injection vulnerability in vote.php in the 2Glux Sexy Polling (com_sexypolling) component before 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the answer_id[] parameter.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| 2glux | com_sexypolling | 0.9.7 |
| 2glux | com_sexypolling | 1.0.2 |
| 2glux | com_sexypolling | 1.0.5 |
| 2glux | com_sexypolling | 1.0.7 |
| 2glux | com_sexypolling | 1.0.3 |
| 2glux | com_sexypolling | 0.9.5 |
| 2glux | com_sexypolling | 0.9.1 |
| 2glux | com_sexypolling | * |
| 2glux | com_sexypolling | 0.9.4 |
| 2glux | com_sexypolling | 1.0.1 |
| 2glux | com_sexypolling | 1.0.4 |
| 2glux | com_sexypolling | 1.0.6 |
| 2glux | com_sexypolling | 0.9.2 |
| 2glux | com_sexypolling | 0.9.6 |