Joomla CMS Pentesting
Scan
joomscan -u https://example.comCommon Directories
/administrator/
/administrator/manifests/files/joomla.xml
/cache/
/components/
/configuration.php
/htaccess.txt
/includes/
/index.php
/joomla.xml
/language/en-GB/en-GB.xml
/libraries/
/LICENSE.txt
/logs/
/media/
/modules/
/plugins/
/README.txt
/templates/
/tmp/
/web.config.txtDefault Credentials
RCE
1. Login as Admin
2. Select Template
3. Inject Arbitrary Code
4. Execute
References
Last updated