Joomlaboard 1.1.x RFI

For all Non-Joomla! security issues. ie 3pd Components etc.

Moderator: General Support Moderators

Forum rules
Locked
User avatar
brian
Joomla! Master
Joomla! Master
Posts: 12804
Joined: Fri Aug 12, 2005 7:19 am
Location: Leeds, UK
Contact:

Joomlaboard 1.1.x RFI

Post by brian » Wed Mar 28, 2007 8:45 am

Potential Remote File Inclusion in
files : /image_upload.php , /file_upload.php

Reported at http://www.milw0rm.com/exploits/3560
"Exploited yesterday... Hacked tomorrow"
Blog http://brian.teeman.net/
Joomla Hidden Secrets http://hiddenjoomlasecrets.com/

Joomaboom
Joomla! Intern
Joomla! Intern
Posts: 73
Joined: Fri Sep 02, 2005 4:19 pm

Re: Joomlaboard 1.1.x RFI

Post by Joomaboom » Wed Mar 28, 2007 3:06 pm

Is this a really old hack? 

According to the Millworm site this is the fix
*** How To Fix It : U can put this code -
defined( '_VALID_MOS' ) or die( 'Catch Me iF u Can ### Patched By Cold z3ro .' ); - after <?php code start

But my 1.1.4 files for file_upload.php and image_upload.php already has that code in them.
defined( '_VALID_MOS' ) or die( 'Direct Access to this location is not allowed.' );


Locked

Return to “3rd Party/Non Joomla! Security Issues”