EIP-2026-108230
PRE-CVEJoomla! Component Catalog 1.0.7 - SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-108230. PoCs published by Larry W. Cashdollar.
AI-analyzed exploit summary The exploit demonstrates an unauthenticated SQL injection vulnerability in Huge-IT Catalog v1.0.7 for Joomla, specifically in the 'load_more_elements_into_catalog' function in ajax_url.php. The provided sqlmap command and payloads confirm the vulnerability, showing error-based, time-based, and UNION-based SQL injection techniques.
Description
Joomla! Component Catalog 1.0.7 - SQL Injection
Exploits (1)
The exploit demonstrates an unauthenticated SQL injection vulnerability in Huge-IT Catalog v1.0.7 for Joomla, specifically in the 'load_more_elements_into_catalog' function in ajax_url.php. The provided sqlmap command and payloads confirm the vulnerability, showing error-based, time-based, and UNION-based SQL injection techniques.