CVE-2010-1372
HD FLV Player (com_hdflvplayer) 1.3 - SQL Injection via id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-1372. PoCs published by kaMtiEz.
AI-analyzed exploit summary This Perl script exploits an SQL injection vulnerability in the HD FLV Player Joomla component (CVE-2010-1372) by injecting a UNION-based query to extract admin credentials from the jos_users table. It uses LWP::UserAgent to send a crafted HTTP request and parses the response for MD5 password hashes.
Description
SQL injection vulnerability in the HD FLV Player (com_hdflvplayer) component 1.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
Exploits (1)
This Perl script exploits an SQL injection vulnerability in the HD FLV Player Joomla component (CVE-2010-1372) by injecting a UNION-based query to extract admin credentials from the jos_users table. It uses LWP::UserAgent to send a crafted HTTP request and parses the response for MD5 password hashes.