CVE-2018-7178
CRITICALSaxum Picker 3.2.10 - SQL Injection via Publicid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-7178. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Joomla! Component Saxum Picker 3.2.10. The PoC uses the `publicid` parameter to inject a malicious SQL query that extracts database information, including the username, database name, and version.
Description
SQL Injection exists in the Saxum Picker 3.2.10 component for Joomla! via the publicid parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Joomla! Component Saxum Picker 3.2.10. The PoC uses the `publicid` parameter to inject a malicious SQL query that extracts database information, including the username, database name, and version.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H