SECUNIA ADVISORY ID: SA45525 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/45525/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=45525 RELEASE DATE: 2011-08-11DESCRIPTION: A vulnerability has been discovered in TNR ESearch component for Joomla!, which can be exploited by malicious people to conduct SQL injection attacks. Input passed to the "searchId" parameter in components/com_esearch/esearch.php is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. The vulnerability is confirmed in version 3.0.0. Other versions may also be affected. SOLUTION: Edit the source code to ensure that input is properly sanitised. PROVIDED AND/OR DISCOVERED BY: NoGe ORIGINAL ADVISORY: http://www.exploit-db.com/exploits/17646/