EIP-2026-108521
PRE-CVEJoomla! Component com_rsgallery2 2.0 - 'catid' SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-108521. PoCs published by snakespc.
AI-analyzed exploit summary The exploit demonstrates an SQL injection vulnerability in the 'com_rsgallery2' component for Joomla! by injecting a UNION-based SQL query to extract user credentials (username and password) from the 'jos_users' table. The attack leverages insufficient input sanitization in the 'catid' parameter.
Description
Joomla! Component com_rsgallery2 2.0 - 'catid' SQL Injection
Exploits (1)
The exploit demonstrates an SQL injection vulnerability in the 'com_rsgallery2' component for Joomla! by injecting a UNION-based SQL query to extract user credentials (username and password) from the 'jos_users' table. The attack leverages insufficient input sanitization in the 'catid' parameter.