CVE-2018-6396
CRITICALGoogle Map Landkarten <= 4.2.3 - SQL Injection via cid/id/map Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2018-6396. PoCs published by Ihsan Sencan, JavierOlmedo.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Joomla! Component Google Map Landkarten <= 4.2.3. It includes multiple proof-of-concept URLs with crafted SQL payloads to extract database information such as schema names, user credentials, and version details.
Description
SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a layout=form_markers action, or the map parameter in a layout=default action.
Exploits (2)
This exploit demonstrates SQL injection vulnerabilities in Joomla! Component Google Map Landkarten <= 4.2.3. It includes multiple proof-of-concept URLs with crafted SQL payloads to extract database information such as schema names, user credentials, and version details.
This repository contains a Python script that automates the detection and exploitation of an SQL injection vulnerability (CVE-2018-6396) in the Joomla! Component Google Map Landkarten <= 4.2.3. The script checks for vulnerability and launches SQLmap for further exploitation.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H