CVE-2008-0801
PAXXGallery (com_paxxgallery) 0.2 - SQL Injection via iid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0801. PoCs published by S@BUN.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in the Joomla com_paxxgallery component, allowing an attacker to extract user credentials (username and password) from the jos_users table via a crafted URL parameter.
Description
SQL injection vulnerability in index.php in the PAXXGallery (com_paxxgallery) 0.2 component for Mambo and Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the iid parameter in a view action, and possibly (2) the userid parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in the Joomla com_paxxgallery component, allowing an attacker to extract user credentials (username and password) from the jos_users table via a crafted URL parameter.