CVE-2018-17377
CRITICALQuestions 1.4.3 - SQL Injection via Term Userid Users or Groups Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-17377. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in Joomla! Component Questions 1.4.3 via multiple endpoints, allowing unauthorized database information extraction. It includes crafted SQL payloads for UNION-based and error-based injection techniques.
Description
SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter.
Exploits (1)
The exploit demonstrates SQL injection vulnerabilities in Joomla! Component Questions 1.4.3 via multiple endpoints, allowing unauthorized database information extraction. It includes crafted SQL payloads for UNION-based and error-based injection techniques.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H