CVE-2017-20271

HIGH

Joomla StreetGuessr Game 1.1.8 SQL Injection via catid

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-20271. PoCs published by Ihsan Sencan.

AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in Joomla! Component StreetGuessr Game v1.1.8 via the 'catid' parameter. The payload uses MySQL-specific functions to extract database information, confirming the vulnerability.

Description

Joomla StreetGuessr Game 1.1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the catid parameter. Attackers can send GET requests to index.php with the option=com_streetguess&view=maps parameters and inject SQL code in the catid parameter to extract sensitive database information including version and database names.

Exploits (1)

exploitdb WORKING POC
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/42423

The exploit demonstrates a SQL injection vulnerability in Joomla! Component StreetGuessr Game v1.1.8 via the 'catid' parameter. The payload uses MySQL-specific functions to extract database information, confirming the vulnerability.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Joomla! Component StreetGuessr Game v1.1.8
No auth needed
Prerequisites: Joomla! Component StreetGuessr Game v1.1.8 installed
devstral-2 · analyzed Jun 19, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit exploit
ExploitDB-42423
https://www.exploit-db.com/exploits/42423
Third Party Advisory third-party-advisory
VulnCheck Advisory: Joomla StreetGuessr Game 1.1.8 SQL Injection via catid
https://www.vulncheck.com/advisories/joomla-streetguessr-game-sql-injection-via-catid

Scores

CVSS v3 8.2
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Details

CWE
CWE-89
Status published
Products (1)
Nordmograph/StreetGuessr Game 1.1.8
Published Jun 19, 2026
Tracked Since Jun 19, 2026