Trustwave SpiderLabs researcher Asaf Orpani has discovered an SQL injection vulnerability in versions 3.2 through 3.4.4 of Joomla!, a popular open-source Content Management System (CMS). Combining that vulnerability with other security weaknesses, our Trustwave SpiderLabs researchers are able to gain full administrative access to any vulnerable Joomla site.
Upgrade to Joomla! version 3.4.5.
WordPress Plugin ZM Gallery SQL Injection (1.0)
WordPress Plugin PureHTML 'alter.php' SQL Injection (1.0.0)
WordPress Plugin Simple Membership SQL Injection (4.0.3)
WordPress Plugin Sharebar Cross-Site Scripting and SQL Injection Vulnerabilities (1.2.1)
WordPress Plugin Contact Form by WD-responsive drag & drop contact form builder tool SQL Injection (1.7.30)