CVE-2008-0686
Joomla com_neoreferences 1.3.1 and 1.3.3 - SQL Injection via catid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0686. PoCs published by S@BUN.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in the Joomla NeoReferences component (com_neoreferences). The PoC uses a crafted URL to extract user credentials (username and password) from the jos_users table via a UNION-based SQL injection.
Description
SQL injection vulnerability in index.php in the NeoReferences (com_neoreferences) 1.3.1 and 1.3.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in the Joomla NeoReferences component (com_neoreferences). The PoC uses a crafted URL to extract user credentials (username and password) from the jos_users table via a UNION-based SQL injection.