--------------------------------------------------------------------------- Guestbook Mambo Module <== v1.3.0 Multiple Remote File Include Vulnerabilities --------------------------------------------------------------------------- Author : Matdhule Date : July 27th 2006 Location : Indonesia, Jakarta Critical Lvl : Highly critical Impact : System access Where : From Remote --------------------------------------------------------------------------- Affected software description: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Guestbook Module for Mambo Application : Guestbook Module version : 1.3.0 --------------------------------------------------------------------------- Vulnerability: ~~~~~~~~~~~~~~~ in folder components we found vulnerability script com_guestbook.php. -----------------------com_guestbook.php----------------------