CVE-2010-2255
Tamlyncreative Com Bfsurvey Profree < 1.3.0 - SQL Injection
Title source: ruleExploitation Summary
EIP tracks 1 public exploit for CVE-2010-2255. PoCs published by FL0RiX.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in the Joomla component com_bfsurvey_basic, allowing an attacker to extract user credentials (username and password) from the jos_users table via a crafted UNION-based SQL injection payload.
Description
SQL injection vulnerability in the BF Survey Pro (com_bfsurvey_pro) component before 1.3.1, BF Survey Pro Free (com_bfsurvey_profree) component 1.2.6, and BF Survey Basic component before 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in the Joomla component com_bfsurvey_basic, allowing an attacker to extract user credentials (username and password) from the jos_users table via a crafted UNION-based SQL injection payload.