Joomla! Component KissGallery 1.0.0 SQL Injection
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.8epss 0.4%
exploitation probability
0.4%top 63% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the component URL path. Attackers can supply malicious SQL code in the kissgallery endpoint to execute arbitrary database queries and extract sensitive information.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
Terrywcarter · KissGallerypublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/42494unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.