CVE-2017-20273
HIGHJoomla Event Registration Pro Calendar 4.1.3 SQL Injection
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2017-20273. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in Joomla! Component Event Registration Pro Calendar v4.1.3 via the 'id' parameter in the 'category' view. The provided payload uses a UNION-based SQL injection to extract data from the information_schema.columns table.
Description
Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_registrationpro&view=category&id parameter containing SQL injection payloads to extract sensitive database information.
Exploits (1)
The exploit demonstrates a SQL injection vulnerability in Joomla! Component Event Registration Pro Calendar v4.1.3 via the 'id' parameter in the 'category' view. The provided payload uses a UNION-based SQL injection to extract data from the information_schema.columns table.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N