what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Joomla Mosets Tree 2.1.5 Shell Upload

Joomla Mosets Tree 2.1.5 Shell Upload
Posted Sep 14, 2010
Authored by jdc

The Joomla Mosets Tree component version 2.1.5 suffers from a shell upload vulnerability.

tags | exploit, shell
SHA-256 | b4f9b0da401d6d4a284a63fd6113e51059b65d8468309fb75ff018ce670a113b

Joomla Mosets Tree 2.1.5 Shell Upload

Change Mirror Download
# Exploit Title: Joomla Component Mosets Tree 2.1.5 Shell Upload Vulnerability
# Date: 6 September 2010
# Author: jdc
# Software Link: http://www.mosets.com/tree/
# Version: 2.1.5
# Patched: 2.1.6
# Tested on: PHP5, MySQL5

Mosets Tree suffers from a shell upload vulnerabilty caused by
improperly checking the filetype of uploaded images.

Tools used:
-----------
1. Firefox web browser
2. Firebug extension
3. GIMP image editor

Steps to Reproduce:
-------------------
1. Open GIMP, create a new image.
2. Save image as a GIF file, with the shell as the comment (surrounded
by <?php ?> tags).
3. Rename GIF to shell.gif.php
4. Create an account on the target site
5. Navigate to the mtree entry form
6. Fill out all mandatory form fields
7. At the bottom of the form you should be able to add images. Add your
shell.
8. Open Firebug and navigate to the Console tab
9. At the bottom of the console, type this in & hit enter:

(document.getElementById('adminForm')).submit();

10. After the form submits, you should be on your user listing page
11. Navigate to
http://{target}/components/com_mtree/img/listings/o/{id}.php where {id}
is the id number of your new entry

Caveats:
--------
* Requires a registered account
* The shell will have GIF garbage before the PHP code, so headers will already be sent...
* Works if image processing is set to GD or ImageMagick. NetPbm untested.

Greets: Sid3^effects, lafrance (happy birthday old man!)

Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    0 Files
  • 9
    Sep 9th
    0 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    0 Files
  • 12
    Sep 12th
    0 Files
  • 13
    Sep 13th
    0 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close