Changes suggested by h00die 0803
parent
048d0d1fe4
commit
37bf4d118a
|
@ -1,7 +1,7 @@
|
|||
## Vulnerable Application
|
||||
|
||||
This module exploits a SQL Injection vulnerability in the com_fields component which was introduced to the core of Joomla in version 3.7.0.
|
||||
With the SQLi, its possible to enumerate cookies of administrative users, and hijack one of their sessions. If no administrators are authenticated, the RCE portion will not work. If a session hijack is available, one of the website templates is identified, and our payload is added to the template as a new file, and then executed.
|
||||
This module exploits a SQL Injection vulnerability in the 'com_fields' component which was introduced to the core of Joomla in version 3.7.0.
|
||||
With the SQLi, it's possible to enumerate cookies of administrative users, and hijack one of their sessions. If no administrators are authenticated, the RCE portion will not work. If a session hijack is available, one of the website templates is identified, and our payload is added to the template as a new file, and then executed.
|
||||
|
||||
## Verification
|
||||
|
||||
|
|
Loading…
Reference in New Issue