Joomla! Realpin 1.5.04 SQL Injection

Joomla! Realpin component versions 1.5.04 and below suffer from a remote SQL injection vulnerability.


MD5 | f341870abe8320bc76d0cf813790b145

# # # #
# Exploit Title: Joomla! Component Realpin <= 1.5.04 - SQL Injection
# Dork: N/A
# Date: 16.02.2018
# Vendor Homepage: http://realpin.frumania.com/
# Software Link: https://extensions.joomla.org/extensions/extension/multimedia/multimedia-display/realpin/
# Software Download: http://realpin.frumania.com/downloads/com_realpin_j3.1_1.5.04.zip
# Version: <= 1.5.04
# Category: Webapps
# Tested on: WiN7_x64/KaLiLinuX_x64
# CVE: CVE-2018-6005
# # # #
# Exploit Author: Ihsan Sencan
# # # #
#
# POC:
#
# 1)
# http://localhost/[PATH]/index.php?option=com_realpin&pinboard=[SQL]
#
# # # #


Related Posts