CVE-2008-0832
Kemas Antonius com_quran < 1.1 - SQL Injection via surano Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0832. PoCs published by Don.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in the Qur'an component for Mambo and Joomla CMS. It allows an attacker to extract user credentials (username and password) from the database via a UNION-based SQL injection in the 'surano' parameter.
Description
SQL injection vulnerability in index.php in the Kemas Antonius com_quran 1.1 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the surano parameter in a viewayat action.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in the Qur'an component for Mambo and Joomla CMS. It allows an attacker to extract user credentials (username and password) from the database via a UNION-based SQL injection in the 'surano' parameter.