CVE-2009-2239
Joomla com_casinobase, com_casino_blackjack, com_casino_videopoker 0.3.1 - SQL Injection via Itemid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2239. PoCs published by ByALBAYX.
AI-analyzed exploit summary This Perl script exploits SQL injection vulnerabilities in multiple Joomla modules (com_casino_blackjack, com_casinobase, com_casino_videopoker) to extract admin username and password hashes from the jos_users table.
Description
SQL injection vulnerability in the (1) casinobase (com_casinobase), (2) casino_blackjack (com_casino_blackjack), and (3) casino_videopoker (com_casino_videopoker) components 0.3.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.
Exploits (1)
This Perl script exploits SQL injection vulnerabilities in multiple Joomla modules (com_casino_blackjack, com_casinobase, com_casino_videopoker) to extract admin username and password hashes from the jos_users table.