40 lines
No EOL
2.2 KiB
Text
40 lines
No EOL
2.2 KiB
Text
1 ########################################## 1
|
|
0 I'm Sid3^effects member from Inj3ct0r Team 1
|
|
1 ########################################## 0
|
|
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1
|
|
|
|
Name : Joomla Front-End Article Manager System Upload Vulnerability
|
|
Date : july 4,2010
|
|
Critical Level : HIGH
|
|
vendor URL :http://b-elektro.no/
|
|
Author : Sid3^effects aKa HaRi <shell_c99[at]yahoo.com>
|
|
special thanks to : r0073r (inj3ct0r.com),L0rd CruSad3r,MaYur,MA1201,KeDar,Sonic,gunslinger_
|
|
greetz to :www.topsecure.net ,All ICW members and my friends :) luv y0 guyz
|
|
#######################################################################################################
|
|
Description:
|
|
The Front-end article manager system is a simple and very powerful extention, that allows users to manage articles directly from front-end. The system is an article manager that povides various of features, like management of articles,create,edit,delete, publish, approval, notification etc.
|
|
|
|
The system also provides some access control based on user groups or individual users.This gives you the opportunity to create personal blogs, front-end approvement systems, create submition restriction and so on. The users and administrator of the site no longer need to use, or learn how to navigate in back-end to manage articles.
|
|
The system consists of two modules for creating and deleting articles,
|
|
and a template overrider.
|
|
|
|
#######################################################################################################
|
|
Xploit :Upload Vulnerability
|
|
|
|
DEMO URL :http://server/
|
|
|
|
Step 1 : Register :D
|
|
|
|
Step 2 : Now go to your page and select "NEW "
|
|
|
|
DEMO URL:http://server/index.php?view=article&id=9312&task=edit&option=com_content&ret=aHR0cDovL2ItZWxla3Ryby5za2oubm8vaW5kZXgucGhwP29wdGlvbj1jb21fY29udGVudCZ2aWV3PWNhdGVnb3J5JmxheW91dD1ibG9nJmlkPTExJkl0ZW1pZD0xOA==
|
|
|
|
Step 3 : Now upload the evil php script in the text place :P
|
|
|
|
Step 4 : now check your blog and upload the shell
|
|
|
|
DEMO URL :http://server/index.php?option=com_content&view=category&layout=blog&id=11&Itemid=18
|
|
|
|
###############################################################################################################
|
|
# 0day no more
|
|
# Sid3^effects |