sábado, 17 de mayo de 2008 | Online desde el 2005
 
 
Mambo Component e Include Vulnerability PDF Imprimir E-Mail
com_forum Mambo Component <= 1.2.4RC3 Remote Include Vulnerability

Bug Found by h4ntu  | Another Mambo component remote inclusion vulneribility download

http://mamboxchange.com/frs/download...nt1.2.4RC3.zip

bug found in file : download.php

define('IN_PHPBB', true);
//$phpbb_root_path = './';
include($phpbb_root_path . 'extension.inc ');
include($phpbb_root_path . 'common.'.$phpEx);

 
Posible solución a la vulnerabilidad [No testeado]

 
< Anterior   Siguiente >