CVE-2007-4456
Mambo SimpleFAQ Component - SQL Injection via aid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-4456. PoCs published by k1tk4t.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Mambo Component SimpleFAQ V2.11. It leverages a union-based SQL injection to extract username and password from the mos_users table.
Description
SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrary SQL commands via the aid parameter. NOTE: it was later reported that 2.40 is also affected, and that the component can be used in Joomla! in addition to Mambo.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Mambo Component SimpleFAQ V2.11. It leverages a union-based SQL injection to extract username and password from the mos_users table.