7.5
CVSSv2

CVE-2018-5975

Published: 17/02/2018 Updated: 02/03/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL Injection exists in the Smart Shoutbox 3.0.0 component for Joomla! via the shoutauthor parameter to the archive URI.

Vulnerable Product Search on Vulmon Subscribe to Product

thekrotek smart shoutbox 3.0.0

Exploits

# # # # # Exploit Title: Joomla! Component Smart Shoutbox 300 - SQL Injection # Dork: N/A # Date: 16022018 # Vendor Homepage: thekrotekcom/ # Software Link: extensionsjoomlaorg/extension/smart-shoutbox/ # Version: 300 # Category: Webapps # Tested on: WiN7_x64/KaLiLinuX_x64 # CVE: CVE-2018-5975 # # # # # Exploit Author: Ihs ...
Joomla! Smart Shoutbox component version 300 suffers from a remote SQL injection vulnerability ...