CVE-2008-2892
EXP Shop Component 1.0 for Joomla! - SQL Injection via catid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2892. PoCs published by His0k4.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in the Joomla expshop component. It allows an attacker to extract sensitive information such as usernames and passwords from the database by manipulating the 'catid' parameter.
Description
SQL injection vulnerability in the EXP Shop (com_expshop) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show_payment action to index.php.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in the Joomla expshop component. It allows an attacker to extract sensitive information such as usernames and passwords from the database by manipulating the 'catid' parameter.