Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 154343 - www-apps/joomla < 1.0.11 remote file include
Summary: www-apps/joomla < 1.0.11 remote file include
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://seclists.org/bugtraq/2006/Nov/...
Whiteboard: B4 [upstream?]
Keywords:
Depends on:
Blocks:
 
Reported: 2006-11-07 04:24 UTC by Matt Drew (RETIRED)
Modified: 2006-12-29 13:52 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matt Drew (RETIRED) gentoo-dev 2006-11-07 04:24:33 UTC
Can web-apps confirm that this is remotely executable?  Looks like it uses an administrative URL.
Comment 1 Matt Drew (RETIRED) gentoo-dev 2006-11-07 04:25:02 UTC
s/executable/exploitable.
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-11-20 22:34:51 UTC
Follow up on BT. If this is correct it should be closed as INVALID.

1. The installation directory is to be removed after the installation 
 of Joomla!. If you do not follow the instructions - your fault. Having 
 the installation files still on your webserver makes your whole server 
 totally prone of being hijacked, since you can rewrite the configuration. 
 So no need for some remote file inclusion when you can just reset the 
 site with install files... 
 
2. The admin.admin.html.php file is not directly accessible: 
 "// no direct access 
 defined( '_VALID_MOS' ) or die( 'Restricted access' );" 
 So I do not see how this could be exploitable at all. 
 
Anyways, this all only works if you have register_globals enabled, 
 which is strongly discouraged by Joomla!, it even gives you big 
 red warnings to turn it off everytime you enter the admin backend. 
 Hacks is what you get when ignoring security warnings. 
 
regards 
         Sascha 
Comment 3 Matt Drew (RETIRED) gentoo-dev 2006-12-29 13:52:18 UTC
Resolving as INVALID - we've already updated past this.