CVE-2008-1460
com_joovideo 1.0 and 1.2.2 - SQL Injection via id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1460. PoCs published by S@BUN.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in the Mambo component com_joovideo (Powered by joovideo V1.0). The exploit uses a crafted URL to extract user credentials (username and password) from the jos_users table via a UNION-based SQL injection.
Description
SQL injection vulnerability in the Joovideo (com_joovideo) 1.0 and 1.2.2 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in the Mambo component com_joovideo (Powered by joovideo V1.0). The exploit uses a crafted URL to extract user credentials (username and password) from the jos_users table via a UNION-based SQL injection.