CVE-2008-7033
Simple Shop Galore (com_simpleshop) - SQL Injection via Section Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-7033. PoCs published by S@BUN.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in the Simple Shop component for Joomla! and Mambo. The PoC uses a crafted URL to extract user credentials (username and password) from the jos_users table via a UNION-based SQL injection.
Description
SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section action to index.php, a different vulnerability than CVE-2008-2568. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in the Simple Shop component for Joomla! and Mambo. The PoC uses a crafted URL to extract user credentials (username and password) from the jos_users table via a UNION-based SQL injection.