17 lines
No EOL
565 B
Text
17 lines
No EOL
565 B
Text
# Exploit Title: Joomla com_publisher component SQL Injection vulnerability
|
|
# Exploit Author: s0nk3y
|
|
# Date: 21-06-2016
|
|
# Software Link: http://extensions.joomla.org/extension/publisher-pro
|
|
# Category: webapps
|
|
# Version: All
|
|
# Tested on: Ubuntu 16.04
|
|
|
|
1. Description
|
|
Publisher Pro is the ultimate publishing platform for Joomla, turning your
|
|
site into a professional news portal or a magazine that people want to read!
|
|
|
|
2. Proof of Concept
|
|
|
|
Itemid Parameter Vulnerable To SQL Injection
|
|
|
|
http://server/index.php?option=com_publisher&view=issues&Itemid=[SQLI]&lang=en |