Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-25759. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This is a functional SQL injection exploit for Joomla! Component vBizz 1.0.7. The exploit demonstrates a time-based blind SQL injection via the 'payid[]' parameter in a POST request, using the 'AND EXTRACTVALUE' function to trigger a database error and extract version information.
Description
Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the payid parameter. Attackers can submit POST requests to the employee management interface with crafted payid array values containing SQL commands to extract sensitive database information including version and database names.
Exploits (1)
This is a functional SQL injection exploit for Joomla! Component vBizz 1.0.7. The exploit demonstrates a time-based blind SQL injection via the 'payid[]' parameter in a POST request, using the 'AND EXTRACTVALUE' function to trigger a database error and extract version information.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N