SQL Injection Vulnerability in JE Guestbook for Joomla!
CVE-2010-4865

Currently unrated

Key Information:

Vendor
CVE Published:
5 October 2011

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2010-4865?

The JE Guestbook component version 1.0 for Joomla! is susceptible to an SQL injection vulnerability. This flaw allows remote attackers to manipulate the d_itemid parameter in the item_detail action of index.php, enabling arbitrary SQL command execution. By exploiting this vulnerability, attackers may gain unauthorized access to sensitive data within the database, posing significant risks to the integrity and confidentiality of the web application.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.