[ TITLE ....... ][ Joomla 2.5.4 with components/extensions I found @ webs [ DATE ........ ][ 07.04.2012 [ AUTOHR ...... ][ http://hauntit.blogspot.com [ SOFT LINK ... ][ http://joomla.org [ VERSION ..... ][ 2.5.4 [ TESTED ON ... ][ LAMP [ ----------------------------------------------------------------------- [ [ 1. What is this? [ 2. What is the type of vulnerability? [ 3. Where is bug :) [ 4. More... [--------------------------------------------[ [ 1. What is this? This is very nice CMS, You should try it! ;) [--------------------------------------------[ [ 2. What is the type of vulnerability? When admin add 'the same content' twicely, then he will see an error similar to this: "Duplicate entry 'c9ujq(...)63rscpi5' for key 'PRIMARY' SQL=INSERT INTO `qcd3p_session` (`session_id`, `client_id`, `time`) VALUES ('c9u(...)i5', 1, '1338(...)88')" So now 'attacker' can find out what is the prefix of Your Joomla installation. In other way, this bug is available only from admin. ;) [--------------------------------------------[ [ 3. Where is bug :) http://joomla/administrator/index.php?option=com_installer&view=update&task=%2bunion%2bselect%2bnull--.ajax [--------------------------------------------[ [ 4. More... - http://www.joomla.org - http://hauntit.blogspot.com - http://www.google.com - http://portswigger.net * Why 'with friends' - because I added to my localhost Joomla installation so many extensions (to tests;)), so vulnerable could be else part of CMS too (for example: similar bug I found in latest VirtueMart 2.0.2. Check out at my blog. * [ [--------------------------------------------[ [ All questions about new projects @ mail now :) ] [ Best regards [