95293vdb entry
http://www.securityfocus.com/bid/95293 CVE-2016-10114
CRITICAL
Joomla! Component aWeb Cart Watching System for Virtuemart 2.6.0 - SQL Injection
Record summary
CVE-2016-10114 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in the "aWeb Cart Watching System for Virtuemart" extension before 2.6.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via vectors involving categorysearch and smartSearch.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBJoomla! Component aWeb Cart Watching System for Virtuemart 2.6.0 - SQL InjectionExploitDB exploitby qemmNot analyzed1 file
References
5github.com
https://github.com/qemm/joomlasqli nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-10114 vel.joomla.org
https://vel.joomla.org/resolved/1897-aweb-cart-watching-system-2-6-0 40973exploit
https://www.exploit-db.com/exploits/40973