CVE-2008-0510
Joomla! and Mambo Newsletter Component - SQL Injection via listid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0510. PoCs published by S@BUN.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in the Joomla/Mambo 'com_newsletter' component. It allows an attacker to extract user credentials (name, password) from the 'mos_users' table via a crafted URL.
Description
SQL injection vulnerability in index.php in the Newsletter (com_newsletter) component for Mambo 4.5 and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in the Joomla/Mambo 'com_newsletter' component. It allows an attacker to extract user credentials (name, password) from the 'mos_users' table via a crafted URL.