---
id: CVE-2017-20279
title: Joomla Payage 2.05 SQL Injection via aid Parameter
summary: >-
  Joomla Payage 2.05 contains an SQL injection vulnerability that allows
  unauthenticated attackers to manipulate database queries by injecting SQL code
  through the aid parameter. Attackers can send GET requests to index.php with
  malicious …
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-89
vendor: Extensions
product: Joomla Payage
affected:
  - joomla_payage 2.05
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-06-22T14:21:19.373231Z'
exploitAvailable: true
published: '2026-06-19'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:07.164Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2017-20279'
references:
  - url: 'https://www.exploit-db.com/exploits/42113'
    label: ExploitDB-42113
  - url: >-
      https://www.vulncheck.com/advisories/joomla-payage-sql-injection-via-aid-parameter
    label: 'VulnCheck Advisory: Joomla Payage 2.05 SQL Injection via aid Parameter'
tags:
  - cve.org
  - exploit-available
epss: 0.00432
epssPercentile: 0.35228
ingestedAt: '2026-10-01T15:48:17.891Z'
---

## Overview

Joomla Payage 2.05 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the aid parameter. Attackers can send GET requests to index.php with malicious aid values in the make_payment task to extract sensitive database information using boolean-based blind or time-based blind techniques.

## Affected

- `joomla_payage 2.05`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
