Record summary

CVE-2018-12254 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.

Description

router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to a home/requested_user/Sent%20interest/ URI.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBJoomla! Component Ek Rishta 2.10 - SQL InjectionExploitDB exploitby Guilherme AssmannNot analyzed1 file
ExploitDB

PoC details

References

3