/CVE-2017-18345-COM_JOOMANAGER-ARBITRARY-FILE-DOWNLOAD

The Joomanager component through 2.0.0 for Joomla! has an Arbitrary File Download issue, resulting in exposing the Credentials of the DataBase.

Primary LanguagePythonGNU General Public License v3.0GPL-3.0

Version Engine Stage Build

COM_JOOMANAGER 2.0 -ARBITRARY FILE DOWNLOAD

alt tag

Collecting databases in mass with plugin : COM_JOOMANAGER, From CMS: Joomla, Project developed in python 2.x, more information, access the youtube video.

CVE: 2017-18345 Risk: Security Risk High

0day.Today-ID: 29950 ExploitDB-id: 44252

0day db-id: 16348 CXSecurity-id: WLB-2018030054

CVSS v3.0 Severity and Metrics: Base Score: 9.8 CRITICAL

alt tag alt tag alt tag

DEPENDENCES

  • BeautifulSoup
  • Threading
  • urlparse
  • urllib2
  • argparse
  • requests