Exploitation Summary
EIP tracks 1 public exploit for CVE-2015-1477. PoCs published by Sarath Nair.
AI-analyzed exploit summary The exploit demonstrates SQL injection and reflected XSS vulnerabilities in jclassifiedsmanager. The 'id' parameter in the SQLi PoC and the 'view' parameter in the XSS PoC are unsanitized, allowing arbitrary SQL queries and script execution.
Description
SQL injection vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewad task to classifieds/offerring-ads.
Exploits (1)
The exploit demonstrates SQL injection and reflected XSS vulnerabilities in jclassifiedsmanager. The 'id' parameter in the SQLi PoC and the 'view' parameter in the XSS PoC are unsanitized, allowing arbitrary SQL queries and script execution.