Unrated severityNVD Advisory· Published Jun 27, 2008· Updated Apr 23, 2026
CVE-2008-2892
CVE-2008-2892
Description
SQL injection vulnerability in the EXP Shop (com_expshop) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show_payment action to index.php.
Affected products
2- cpe:2.3:a:feellove:exp_shop_component:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:joomla:com_expshop:*:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.