Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-0746. PoCs published by S@BUN.
AI-analyzed exploit summary This exploit demonstrates SQL injection in Joomla's com_gallery component, allowing unauthorized extraction of user credentials (username and password) from the mos_users table. The PoC provides two URL-encoded payloads to bypass authentication and dump sensitive data.
Description
SQL injection vulnerability in index.php in the Gallery (com_gallery) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
Exploits (1)
This exploit demonstrates SQL injection in Joomla's com_gallery component, allowing unauthorized extraction of user credentials (username and password) from the mos_users table. The PoC provides two URL-encoded payloads to bypass authentication and dump sensitive data.