Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-5991. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Joomla! Component Form Maker 3.6.12 via the 'id', 'from', and 'to' parameters. The PoC includes URL-encoded payloads that extract database information such as user, database name, and version.
Description
SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats request, a different vulnerability than CVE-2015-2798.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in Joomla! Component Form Maker 3.6.12 via the 'id', 'from', and 'to' parameters. The PoC includes URL-encoded payloads that extract database information such as user, database name, and version.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H