CVE-2015-6513
j2store < 3.1.6 - SQL Injection via sortby or manufacturer_ids[] Parameter
Title source: llmDescription
Multiple SQL injection vulnerabilities in the J2Store (com_j2store) extension before 3.1.7 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) sortby or (2) manufacturer_ids[] parameter to index.php.
References (3)
Core 3
Core References
Exploit x_refsource_misc
http://packetstormsecurity.com/files/132658/Joomla-J2Store-3.1.6-SQL-Injection.html
Various Sources x_refsource_misc
http://volatileminds.net/2015/07/07/j2store-316-sql-injection.html
Patch, Vendor Advisory x_refsource_confirm
http://j2store.org/download-j2store/j2store-v3-3-1-7.html
Scores
EPSS
0.0217
EPSS Percentile
80.3%
Details
CWE
CWE-89
Status
published
Products (1)
j2store/j2store
< 3.1.6
Published
Aug 18, 2015
Tracked Since
Feb 18, 2026