# Exploit Title: Joomla com_publisher component SQL Injection vulnerability# Exploit Author: s0nk3y# Date: 21-06-2016# Software Link: http://extensions.joomla.org/extension/publisher-pro# Category: webapps# Version: All# Tested on: Ubuntu 16.041. Description
Publisher Pro is the ultimate publishing platform for Joomla, turning your
site into a professional news portal or a magazine that people want to read!
2. Proof of Concept
Itemid Parameter Vulnerable To SQL Injection
http://server/index.php?option=com_publisher&view=issues&Itemid=[SQLI]&lang=en