Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-20276. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Joomla! Component SIMGenealogy v2.1.5. The vulnerability is triggered via the 'type' parameter in the URL, allowing an attacker to inject arbitrary SQL queries.
Description
Joomla! Component SIMGenealogy 2.1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the type parameter. Attackers can send GET requests to index.php with the option=com_simgenealogy, view=latest parameters and inject malicious SQL in the type parameter to extract sensitive database information.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Joomla! Component SIMGenealogy v2.1.5. The vulnerability is triggered via the 'type' parameter in the URL, allowing an attacker to inject arbitrary SQL queries.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N