Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-3661. PoCs published by Chip d3 bi0s.
AI-analyzed exploit summary This exploit demonstrates SQL injection and blind SQL injection vulnerabilities in the Joomla com_djcatalog component. It provides proof-of-concept URLs to extract sensitive information such as usernames and passwords from the database.
Description
Multiple SQL injection vulnerabilities in the DJ-Catalog (com_djcatalog) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a showItem action and (2) cid parameter in a show action to index.php.
Exploits (1)
This exploit demonstrates SQL injection and blind SQL injection vulnerabilities in the Joomla com_djcatalog component. It provides proof-of-concept URLs to extract sensitive information such as usernames and passwords from the database.