CVE-2017-20261
HIGHJoomla! Component Bargain Product VM3 1.0 SQL Injection
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2017-20261. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in Joomla! Component Bargain Product VM3 1.0. It provides a proof-of-concept URL with a crafted SQL payload that can be injected via the 'product_id' parameter in specific views ('brainy' and 'alice').
Description
Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product_id parameter. Attackers can supply crafted SQL statements in GET requests to the brainy and alice views to extract sensitive database information.
Exploits (1)
The exploit demonstrates a SQL injection vulnerability in Joomla! Component Bargain Product VM3 1.0. It provides a proof-of-concept URL with a crafted SQL payload that can be injected via the 'product_id' parameter in specific views ('brainy' and 'alice').
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N