Breaking

Post Top Ad

Monday, March 12, 2018

Joomla Component Proclaim 9.1.1 Arbitrary File Upload Exploit | Cyber World News



cyberworldnews

  • Exploit Title: Joomla! Component Proclaim 9.1.1 - Arbitrary File Upload 
  • Dork: N/A 
  • Date: 22.02.2018 
  • Vendor Homepage: https://www.christianwebministries.org/ 
  • Software Link: https://extensions.joomla.org/extensions/extension/living/religion/proclaim/
  • Software Download: https://github.com/Joomla-Bible-Study/Joomla-Bible-Study/releases/download/v9.1.1/pkg_proclaim.zip 
  • Version: 9.1.1 
  • Category: Webapps 
  • Tested on: WiN7_x64/KaLiLinuX_x64 
  • CVE: CVE-2018-7316 # # 
  • Exploit Author: Ihsan Sencan # # # 
  • POC: # 
  • 1) # http://localhost/[PATH]/index.php?option=com_biblestudy&view=mediafileform&layout=edit&id=1 # http://localhost/[PATH]/images/biblestudy/media/[FILE]

1 comment:

  1. Hey, Wow All the Posts Are Very Informative for the People Who Visit This Site. Good Work! Thank You for Sharing.
    Joomla training in chennai

    ReplyDelete

Post Top Ad

Pages