Joomla! Component com_publisher – SQL Injection

  • 作者: s0nk3y
    日期: 2016-06-21
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/39989/
  • # Exploit Title: Joomla com_publisher component SQL Injection vulnerability
    # Exploit Author: s0nk3y
    # Date: 21-06-2016
    # Software Link: http://extensions.joomla.org/extension/publisher-pro
    # Category: webapps
    # Version: All
    # Tested on: Ubuntu 16.04
    
    1. Description
    Publisher Pro is the ultimate publishing platform for Joomla, turning your
    site into a professional news portal or a magazine that people want to read!
    
    2. Proof of Concept
    
    Itemid Parameter Vulnerable To SQL Injection
    
    http://server/index.php?option=com_publisher&view=issues&Itemid=[SQLI]&lang=en