vendor:
Xe webtv
by:
His0k4
7.5
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: Xe webtv
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Joomla Component Xe webtv Blind SQL Injection Exploit
This exploit is used to gain access to the admin user of a Joomla Component Xe webtv. It uses a blind SQL injection vulnerability to exploit the system. The exploit takes the host, path, category value and valid tv id as arguments. It then sends a GET request to the host with the given path and the category and tv id as parameters. If the exploit is successful, it will return the admin user of the system.
Mitigation:
The best way to mitigate this vulnerability is to update the system to the latest version and apply all security patches.