Tuesday, July 3, 2018

Reggia di caserta SQL Injection system compromise xss etc http www reggiadicaserta beniculturali it

Reggia di caserta SQL Injection system compromise xss etc http www reggiadicaserta beniculturali it




Joomla 1.5.15 (Vulnerable)

http://www.reggiadicaserta.beniculturali.it
Archive.org: https://web.archive.org/web/20170426095201/http://reggiadicaserta.beniculturali.it:80/
They moved to: http://www.reggiadicaserta.beniculturali.it/Joomla/

path: /var/www/reggiadicaserta

They also have malwares (search in the source code http://www.freepokermoney.net or similar urls):

http://www.reggiadicaserta.beniculturali.it/Joomla/index.php?option=com_content&view=article&id=1434:codice-di-comportamento-dei-dipendenti-delle-pubbliche-amministrazioni&catid=212:organico-contatti&Itemid=886

Archived page:http://archive.is/3JJsi


Wordpress 4.8.3 (with bogus plugin and theme)

http://www.reggiadicaserta.beniculturali.it/wp/




the wordpress version is the "new" website and they also "devastated" the, already bad (with malwares), seo optimization by not redirecting urls. I feel very sorry for that. What a mess.





visit link download