CVE-2009-3335

TurtuShout 0.11 - SQL Injection via Name Field

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-3335. PoCs published by jdc.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in the Joomla Component Turtushout 0.11. The payload injects a malicious SQL query into the 'Name' field to extract username and email from the #__users table where gid=25 (likely admin users).

Description

SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.

Exploits (1)

exploitdb WORKING POC VERIFIED
by jdc · textwebappsphp
https://www.exploit-db.com/exploits/9653

This exploit demonstrates a SQL injection vulnerability in the Joomla Component Turtushout 0.11. The payload injects a malicious SQL query into the 'Name' field to extract username and email from the #__users table where gid=25 (likely admin users).

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Joomla Component Turtushout 0.11
No auth needed
Prerequisites: Access to the vulnerable Joomla component input field
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9653
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/53209

Scores

EPSS 0.0093
EPSS Percentile 55.8%

Details

CWE
CWE-89
Status published
Products (1)
turtus/turtushout 0.11
Published Sep 24, 2009
Tracked Since Feb 18, 2026