CVE-2011-4823

Extensionsforjoomla Com Vikrealestate - SQL Injection

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2011-4823. PoCs published by the_cyber_nuxbie, Chris Russell.

AI-analyzed exploit summary The provided text describes SQL injection vulnerabilities in the 'com_sanpham' component for Joomla! due to insufficient sanitization of user-supplied data. It includes example URLs demonstrating the vulnerable parameters.

Description

Multiple SQL injection vulnerabilities in Vik Real Estate (com_vikrealestate) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) contract parameter in a results action and (2) imm parameter in a show action to index.php.

Exploits (2)

exploitdb WRITEUP VERIFIED
by the_cyber_nuxbie · textwebappsphp
https://www.exploit-db.com/exploits/36592

The provided text describes SQL injection vulnerabilities in the 'com_sanpham' component for Joomla! due to insufficient sanitization of user-supplied data. It includes example URLs demonstrating the vulnerable parameters.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Joomla! with 'com_sanpham' component
No auth needed
Prerequisites: Access to the vulnerable Joomla! instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Chris Russell · textwebappsphp
https://www.exploit-db.com/exploits/18048

The document describes two blind SQL injection vulnerabilities in the Vik Real Estate 1.0 Joomla component, affecting the 'contract' and 'imm' parameters. It provides example URLs demonstrating the vulnerabilities but does not include executable exploit code.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Vik Real Estate 1.0 (Joomla component)
No auth needed
Prerequisites: Joomla installation with Vik Real Estate 1.0 component
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18048

Scores

EPSS 0.0102
EPSS Percentile 58.9%

Details

CWE
CWE-89
Status published
Products (1)
extensionsforjoomla/com_vikrealestate 1.0
Published Dec 15, 2011
Tracked Since Feb 18, 2026