Exploits / Vulnerability Discovered : 2019-02-28 |
Type : webapps |
Platform : php
This exploit / vulnerability Joomla! component j2store < 3.3.7 sql injection is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
# Exploit Title: J2Store Plugin for Joomla! < 3.3.6 - SQL Injection
# Date: 19/02/2019
# Author: Andrei Conache
# Twitter: @andrei_conache
# Contact: andrei.conache[at]protonmail.com
# Software Link: https://www.j2store.org
# Version: 3.x-3.3.6
# Tested on: Linux
# CVE: CVE-2019-9184
1. Description:
J2Store is the most popular shopping/e-commerce extension for Joomla!. The SQL Injection found allows any visitor to run arbitrary queries
on the website.