Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-6605 PoC — Joomla! Zh BaiduMap SQL注入漏洞

Source
Associated Vulnerability
Title:Joomla! Zh BaiduMap SQL注入漏洞 (CVE-2018-6605)
Description:Joomla!是美国Open Source Matters团队开发的一套开源的内容管理系统(CMS),该系统提供RSS馈送、网站搜索等功能。Zh BaiduMap是使用在其中的一个百度地图组件。 Joomla! Zh BaiduMap 3.0.0.1版本中存在SQL注入漏洞。远程攻击者可借助getPlacemarkDetails、getPlacemarkHoverText、getPathHoverText或getPathDetails请求中的‘id’参数利用该漏洞注入SQL命令。
Description
SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request.
File Snapshot

id: CVE-2018-6605 info: name: Joomla! Component Zh BaiduMap 3.0.0.1 - SQL Injection author: Dhi ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.