CVE-2018-6396

CRITICAL

Google Map Landkarten <= 4.2.3 - SQL Injection via cid/id/map Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2018-6396. PoCs published by Ihsan Sencan, JavierOlmedo.

AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Joomla! Component Google Map Landkarten <= 4.2.3. It includes multiple proof-of-concept URLs with crafted SQL payloads to extract database information such as schema names, user credentials, and version details.

Description

SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a layout=form_markers action, or the map parameter in a layout=default action.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/44113

This exploit demonstrates SQL injection vulnerabilities in Joomla! Component Google Map Landkarten <= 4.2.3. It includes multiple proof-of-concept URLs with crafted SQL payloads to extract database information such as schema names, user credentials, and version details.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Joomla! Component Google Map Landkarten <= 4.2.3
No auth needed
Prerequisites: Access to the vulnerable Joomla component
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 8 stars
by JavierOlmedo · poc
https://github.com/JavierOlmedo/joomla-cve-2018-6396

This repository contains a Python script that automates the detection and exploitation of an SQL injection vulnerability (CVE-2018-6396) in the Joomla! Component Google Map Landkarten <= 4.2.3. The script checks for vulnerability and launches SQLmap for further exploitation.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Joomla! Component Google Map Landkarten <= 4.2.3
No auth needed
Prerequisites: Target URL with vulnerable Joomla component · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://exploit-db.com/exploits/44113
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/103094

Scores

CVSS v3 9.8
EPSS 0.2442
EPSS Percentile 97.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
google_map_landkarten_project/google_map_landkarten < 4.2.3
Published Feb 17, 2018
Tracked Since Feb 18, 2026