header-logo
Suggest Exploit
vendor:
QuickFAQ
by:
RoAd_KiLlEr
8,8
CVSS
HIGH
BSQL-i Vulnerability
89
CWE
Product Name: QuickFAQ
Affected Version From: 1.0.3
Affected Version To: 1.0.3
Patch Exists: YES
Related CWE: N/A
CPE: a:schlu.net:quickfaq:1.0.3
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2/SP3
2011

Joomla Component (com_quickfaq) BSQL-i Vulnerability

QuickFAQ is vulnerable to Blind SQL Injection. This vulnerability allows an attacker to execute arbitrary SQL commands on the vulnerable system. The vulnerability is located in the 'cid' parameter of the 'category' value of the 'view' parameter when making a GET request to the vulnerable application. An attacker can inject malicious SQL commands to manipulate the content of the database.

Mitigation:

Upgrade to the latest version of QuickFAQ.
Source

Exploit-DB raw data:

-----------------------------------------------------------------------------------------
 Joomla   Component  (com_quickfaq)  BSQL-i Vulnerability
-----------------------------------------------------------------------------------------
[+]Title                Joomla   Component  (com_quickfaq)  BSQL-i Vulnerability
[+]Author          **RoAd_KiLlEr**
[+]Contact        RoAd_KiLlEr[at]Khg-Crew[dot]Ws
[+]Tested on     Win Xp Sp 2/3
---------------------------------------------------------------------------
[~] Founded by **RoAd_KiLlEr**
[~] Team: Albanian Hacking Crew
[~] Contact: RoAd_KiLlEr[at]Khg-Crew[dot]Ws 
[~] Home: http://inj3ct0r.com
[~] Vendor: http://www.schlu.net
[~] Download Application:http://www.schlu.net/downloads/16-component/77-quickfaq.html
[~] Version: 1.0.3
==========ExPl0iT3d by **RoAd_KiLlEr**==========

[+]Description:
QuickFAQ is an easy to use but powerful FAQ management system.

Feature List:
* Unlimited Subcategories
* Assign FAQ Items to multiple Categories
* Create Tags/Labels to flag FAQ Items
* Up/down voting of FAQ Items
* Favoure FAQ Items to maintain a personal bookmark list
* Document uploader/manager
* PDF creation of FAQ Items
* RTL support
* RSS/ATOM Feeds
* Detailed statistics
* JComments and JomComments integration
=========================================

[+] Dork: inurl:"com_quickfaq"

==========================================


[+].  SQL-i Vulnerability
=+=+=+=+=+=+=+=+=+

[Exploit]:  http://127.0.0.1/path/index.php?option=com_quickfaq&view=category&cid=[Valid Cid]&Itemid= [BSQL-Injection]