6.5
CVSSv2

CVE-2018-12254

Published: 12/06/2018 Updated: 02/08/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to a home/requested_user/Sent%20interest/ URI.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

harmistechnology ek rishta 2.10

Exploits

# Title: SQL Injection Joomla Component Ek rishta 210 - SQL Injection # Date: 2018-06-14 # Exploit Author: Guilherme Assmann # Vendor Homepage:wwwjoomlaorg/ # Version: 210 # Tested on: MacOSX, Safari, Chrome # Download: extensionsjoomlaorg/extension/ek-rishta/ # CVE: CVE-2018-12254 # Vulnerability Description # To exploit thi ...
Joomla Ek Rishta component version 210 suffers from a remote SQL injection vulnerability ...