Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-0381. PoCs published by XaDoS.
AI-analyzed exploit summary This Perl script exploits a SQL injection vulnerability in Joomla's BazaarBuilder Shopping Cart Software v.5.0 to extract admin credentials from the jos_users table. It uses a UNION-based SQLi attack to retrieve username and password hashes.
Description
SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a products action to index.php.
Exploits (1)
This Perl script exploits a SQL injection vulnerability in Joomla's BazaarBuilder Shopping Cart Software v.5.0 to extract admin credentials from the jos_users table. It uses a UNION-based SQLi attack to retrieve username and password hashes.