Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-3972. PoCs published by v3n0m.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Joomla's com_siirler component (version 1.2). The PoC uses a UNION-based SQLi to extract username and password hashes from the jos_users table.
Description
SQL injection vulnerability in the Q-Proje Siirler Bileseni (com_siirler) component 1.2 RC for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in an sdetay action to index.php.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Joomla's com_siirler component (version 1.2). The PoC uses a UNION-based SQLi to extract username and password hashes from the jos_users table.