CVE-2009-1848
JoomlaMe AgoraGroups 0.3.5.3 - SQL Injection via id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1848. PoCs published by Chip d3 bi0s.
AI-analyzed exploit summary This is a proof-of-concept for a blind SQL injection vulnerability in the Joomla component com_agoragroup. The exploit demonstrates how to extract user credentials by manipulating the 'id' parameter in the URL.
Description
SQL injection vulnerability in the JoomlaMe AgoraGroups (aka AG or com_agoragroup) component 0.3.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a groupdetail action to index.php.
Exploits (1)
This is a proof-of-concept for a blind SQL injection vulnerability in the Joomla component com_agoragroup. The exploit demonstrates how to extract user credentials by manipulating the 'id' parameter in the URL.