vendor:
EZ Store
by:
His0k4
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: EZ Store
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Joomla Component EZ Store Blind SQL Injection Exploit
This exploit is a blind SQL injection vulnerability in the Joomla Component EZ Store. It allows an attacker to extract the MD5 hash of the admin password from the database. The exploit requires the attacker to know the category value and product id of the target website.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in SQL queries.