9.8
CVSSv3

CVE-2017-17870

Published: 27/12/2017 Updated: 11/01/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.

Vulnerable Product Search on Vulmon Subscribe to Product

jbuildozer jbuildozer 1.4.1

Exploits

# # # # # # Exploit Title: Joomla! Component JBuildozer 141 - SQL Injection # Dork: N/A # Date: 12122017 # Vendor Homepage: jbuildozercom/ # Software Link: extensionsjoomlaorg/extensions/extension/authoring-a-content/content-construction/jbuildozer/ # Version: 141 # Category: Webapps # Tested on: WiN7_x64/KaLiLinuX_x64 # CVE ...