Summary: another backdoored joomla component (yawn)

Application: Jumi, a joomla component

About Jumi:
 Jumi is the set of custom code extensions for Joomla! 1.0.x and 1.5.x in
 their native modes. Since 2006 more then 200.000 downloads.  With Jumi you
 can include php, html, javascript scripts into the modules position,
 articles, category or section descriptions, or into your own custom made
 component pages.
Fun snippet from the release_notes.txt:
 Changes:
   - Fixed: security vulnerability
Vendor notified:
 *.cz .. I looked at the fun pictures on the "about us" screen, and
left it at that.
 Joomla?  A CC of this mail on their "STRIKE TEAM" form (are you
afraid of e-mail gentlemen?)

Download url/s:
 http://extensions.joomla.org/extensions/search/ ... Read more »
Views: 1245 | Added by: apeh1706 | Date: 31 October 2009 | Comments (0)

##############################
#######################################################

Application:  My Remote File Server
           
Platforms:    Windows XP Professional SP2

Exploitation: Privilege Escalation

Date:         2009-10-26

Author:       Francis Provencher (Protek Research Lab's)

         
#####################################################################################

1) Introduction
2) Technical details
3) The Code (N/A)


#####################################################################################

===============
1) Introduction
===============
    

My Remote Files Server Edition is special Windows software that helps to organize simultaneous a ... Read more »
Views: 8522 | Added by: apeh1706 | Date: 31 October 2009 | Comments (0)

close