[] NeoSense

Joomla! Component com_joomnik - SQL Injection

Author: SOLVER
type: webapps
platform: php
port: 
date_added: 2011-05-29 
date_updated: 2016-11-02 
verified: 1 
codes: OSVDB-72741 
tags: 
aliases:  
screenshot_url:  
application_url: http://www.exploit-db.comcom_joomnik_09.zip

<------------------- header data start ------------------- >
#############################################################
Joomla Component Joomnik Gallery SQL Injection Vulnerability
#############################################################

# Author : SOLVER ~ Bug Researchers

# Date : 26.05.2011

# Greetz : DreamPower - CWKOMANDO - Toprak - Equ - Err0r - 10line

# Name : Joomla com_joomnik

# Bug Type : SQL injection

# Infection : Admin Login Bilgileri Alinabilir.

# Example Vuln :

[+]/index.php?option=com_joomnik&album=[EXPLOIT]

[+] Dork:"com_joomnik"

[+] Demo: http://site.com/index.php?option=com_joomnik&album=6'

# Bug Fix Advice : Zararli Karakterler Filtrenmelidir.
#############################################################
http://joomlacode.org/gf/project/joomnik/