VirtueMart eCommerce for Joomla <= 1.1.6 Blind SQL Injection

Andrea Fabrizi <[email protected]>
Newsgroups gmane.comp.security.web-applications,gmane.comp.security.bugtraq
Message-ID <[email protected]>
**************************************************************
Application: VirtueMart
Version affected: <= 1.1.6
Website: http://www.virtuemart.net/
Discovered By: Andrea Fabrizi
Email: [email protected]
Web: http://www.andreafabrizi.it
Vuln: Blind SQL Injection
**************************************************************

Blind SQL Injection found in "search_category" parameter.

Example:
http://127.0.0.1/index.php?category_id=&page=shop.browse&option=com_virtuemart&Itemid=1&keyword1=hand&search_op=and&keyword2=&search_limiter=anywhere&search=Search&search_category=3
AND $BLIND_SQL --

EXPLOIT: http://www.andreafabrizi.it/download.php?file=virtuemart_sql_exploit.sh



This list is sponsored by Cenzic
--------------------------------------
Let Us Hack You. Before Hackers Do!
It's Finally Here - The Cenzic Website HealthCheck. FREE.
Request Yours Now! 
http://www.cenzic.com/2009HClaunch_Securityfocus
--------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.