CVE-2009-3342
AlphaUserPoints 1.5.2 - SQL Injection via Username2Points Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3342. PoCs published by jdc.
AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in Joomla's AlphaUserPoints component (CVE-2009-3342). It extracts admin credentials via blind SQLi, resets the password, and provides a link to log in as the compromised admin.
Description
SQL injection vulnerability in frontend/assets/ajax/checkusername.php in the AlphaUserPoints (com_alphauserpoints) component 1.5.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the username2points parameter.
Exploits (1)
This exploit targets a SQL injection vulnerability in Joomla's AlphaUserPoints component (CVE-2009-3342). It extracts admin credentials via blind SQLi, resets the password, and provides a link to log in as the compromised admin.