--------------------------------------------------------------------------- Mambo/Joomla com_comprofiler Components <== v1.0 RC 2 Multiple Remote File Include Vulnerabilities --------------------------------------------------------------------------- Author : Matdhule Date : August, 25th 2006 Location : Indonesia, Jakarta Critical Lvl : Highly critical Impact : System access Where : From Remote --------------------------------------------------------------------------- Affected software description: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ com_comprofiler Components Application : com_comprofiler version : 1.0 RC 2 --------------------------------------------------------------------------- Vulnerability: ~~~~~~~~~~~~~~~ in folder com_comprofiler we found vulnerability script plugin.class.php -----------------------plugin.class.php----------------------