The Joomla Eventcal component 1.6.4 remote blind SQL injection

2010.07.04
Risk: Medium
Local: No
Remote: Yes
CWE: CWE-89


CVSS Base Score: 7.5/10
Impact Subscore: 6.4/10
Exploitability Subscore: 10/10
Exploit range: Remote
Attack complexity: Low
Authentication: No required
Confidentiality impact: Partial
Integrity impact: Partial
Availability impact: Partial

[~] Founded by **RoAd_KiLlEr** [~] Team: Albanian Hacking Crew [~] Contact: RoAd_KiLlEr[at]Khg-Crew[dot]Ws [~] Home: http://a-h-crew.net [~] Download App:http://joomlacode.org/gf/project/eventcal/frs/ ==========ExPl0iT3d by **RoAd_KiLlEr**========== [+]Description: eventCal is a calendar component for Joomla!. It enables you to provide a month, week and day-overview of events to your users. If enabled, users will be able to submit events from the frontend of your site directly into the calendar. ========================================= [+] Dork: inurl:"com_eventcal" ========================================== [+]. SQL-i Vulnerability =+=+=+=+=+=+=+=+=+ [Exploit]: http://127.0.0.1/path/index.php?option=com_eventcal&Itemid=[BLIND SQL-i] =========================================================================================== [!] Albanian Hacking Crew =========================================================================================== [!] **RoAd_KiLlEr** =========================================================================================== [!] MaiL: sukihack[at]gmail[dot]com =========================================================================================== [!] Greetz To : Ton![w]indowS | X-n3t | b4cKd00r ~ | DarKHackeR. | The|DennY` | EaglE EyE | Lekosta | KHG | THE_1NV1S1BL3 & All Albanian/Kosova Hackers =========================================================================================== [!] Spec Th4nks: Inj3ct0r.com & r0073r | indoushka from Dz-Ghost Team | MaFFiTeRRoR | Sid3^effects | The_Exploited | And All My Friendz =========================================================================================== [!] Red n'black i dress eagle on my chest It's good to be an ALBANIAN Keep my head up high for that flag I die Im proud to be an ALBANIAN ===========================================================================================

References:

http://xforce.iss.net/xforce/xfdb/60060
http://www.securityfocus.com/bid/41369
http://www.exploit-db.com/exploits/14187
http://packetstormsecurity.org/1007-exploits/joomlaeventcal-sql.txt


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2021, cxsecurity.com

 

Back to Top