#################################################################### [+] Exploit Title : CMS 4.x.x Zorder (SQL Injection Vul) [+] Author : Kr4L BeNiM [+] Contact : www.facebook.com/kr4l.hacker [+] Date : November 13, 2011 [+] Software Link: http://mambo-developer.org [+] Category: Web Apps #################################################################### Vulnerability: *SQL injection Vulnerability* [#] Exploit : - The "zorder" parameter was not properly sanitized upon submission to the administrator/index2.php url, which allows attacker to conduct SQL Injection attack. [#] Explaination : - http://target.com/mambo/administrator/index2.php?limit=10&order[]=11&boxchecked=0&toggle=on&search=sqli&task=&limitstart=0&cid[]=on&zorder= (SQL Inj Codes) #################################################################### [+] Greets : Likuid Sky, Hax.Root, S.O.G, DjArs HaXoR, KiLLerMiNd, CyberLeeTs ####################################################################