Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-0799. PoCs published by S@BUN.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in the Joomla Quiz component (com_quiz) via the 'tid' parameter. It allows an attacker to extract usernames and passwords from the database by injecting a UNION-based SQL query.
Description
SQL injection vulnerability in index.php in the Quiz (com_quiz) 0.81 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in the Joomla Quiz component (com_quiz) via the 'tid' parameter. It allows an attacker to extract usernames and passwords from the database by injecting a UNION-based SQL query.