CVE-2018-6581
CRITICALjms_music 1.1.1 - SQL Injection via Search Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-6581. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Joomla! Component JMS Music 1.1.1 via the 'keyword', 'artist', and 'username' parameters. It includes multiple payloads for boolean-based blind, error-based, and time-based blind SQL injection attacks.
Description
SQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username parameter.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in Joomla! Component JMS Music 1.1.1 via the 'keyword', 'artist', and 'username' parameters. It includes multiple payloads for boolean-based blind, error-based, and time-based blind SQL injection attacks.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H