Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-2933. PoCs published by CypherXero.
AI-analyzed exploit summary This script exploits a SQL injection vulnerability in Joomla's Phil-a-Form component (version <= 1.2.0.0) to retrieve admin usernames and MD5 password hashes. It constructs malicious SQL queries via URL parameters and parses the output to extract credentials.
Description
SQL injection vulnerability in index.php in the Phil-a-Form (com_philaform) 1.2.0.0 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the form_id parameter.
Exploits (1)
This script exploits a SQL injection vulnerability in Joomla's Phil-a-Form component (version <= 1.2.0.0) to retrieve admin usernames and MD5 password hashes. It constructs malicious SQL queries via URL parameters and parses the output to extract credentials.