Description Joomla! 组件Reverse Auction Factory 4.3.8版本filter_order_Dir参数存在SQL注入漏洞,攻击者可以利用此漏洞获取数据库敏感信息。
References https://www.exploit-db.com/exploits/45475 https://qkl.seebug.org/vuldb/ssvid-97623 https://www.cve.org/CVERecord?id=CVE-2018-17376 https://www.thesmartscanner.com/vulnerability-list/joomla-component-reverse-auction-factory-4-3-8-sqli https://osv.dev/vulnerability/CVE-2018-17376 https://cve.reconshell.com/cve?vendor=thephpfactory&product=reverse_auction_factory
Related VulnerabilitiesPoCCVE-2026-82329: JFrog Artifactory Access Blank Join Key Authentication BypassPoCCVE-2026-65761: Joomla Easy Store - SQL InjectionPoCCVE-2026-20896: Gitea Docker Image <= 1.26.2 - Reverse Proxy Header Authentication BypassPoCCVE-2026-57827: RSFiles! for Joomla - Arbitrary File UploadPoCCVE-2026-48939: Joomla iCagenda < 3.9.10 - Unauthenticated Arbitrary File Upload RCEPoCjoomla-com-fabrik-lfi: Joomla! com_fabrik 3.9.11 - Local File InclusionPoCCVE-2026-48907: Joomla! JCE extension < 2.9.99.5 unauthenticated RCEJoomla JCE /index.php com_jce 文件上传漏洞(CVE-2026-48907)PoCjfrog-artifactory-build-exposure: JFrog Artifactory Build - ExposurePoCjoomla-fpd: Joomla! - Full Path DisclosurePoCjfrog-artifactory-exposure: JFrog Artifactory Artifacts Exposuredillinger /factory/fetch_pdf 命令执行漏洞