what can I do with this Vulnerability ? 04-04-2012, 05:12 PM
#1
Tell me if I did wrong
I used Backtrack 5 R2 and used Joomscan with a target like this:
./joomscan.pl -u victim.com
now tell me what can I do with this things ?
# 1
Info -> Generic: htaccess.txt has not been renamed.
Versions Affected: Any
Check: /htaccess.txt
Exploit: Generic defenses implemented in .htaccess are not available, so exploiting is more likely to succeed.
Vulnerable? Yes
# 14
Info -> Core: Admin Backend Cross Site Request Forgery Vulnerability
Versions effected: 1.0.13 <=
Check: /administrator/
Exploit: It requires an administrator to be logged in and to be tricked into a specially crafted webpage.
Vulnerable? Yes
# 34
Info -> CoreComponent: com_mailto timeout Vulnerability
Versions effected: 1.5.13 <=
Check: /components/com_mailto/
Exploit: [Requires a valid user account] In com_mailto, it was possible to bypass timeout protection against sending automated emails.
Vulnerable? Yes
and lot of Vulnerable? No
these are yes what can i Do ? is it possible to hack this site ? to deface this site ?:headbash:
I used Backtrack 5 R2 and used Joomscan with a target like this:
./joomscan.pl -u victim.com
now tell me what can I do with this things ?
# 1
Info -> Generic: htaccess.txt has not been renamed.
Versions Affected: Any
Check: /htaccess.txt
Exploit: Generic defenses implemented in .htaccess are not available, so exploiting is more likely to succeed.
Vulnerable? Yes
# 14
Info -> Core: Admin Backend Cross Site Request Forgery Vulnerability
Versions effected: 1.0.13 <=
Check: /administrator/
Exploit: It requires an administrator to be logged in and to be tricked into a specially crafted webpage.
Vulnerable? Yes
# 34
Info -> CoreComponent: com_mailto timeout Vulnerability
Versions effected: 1.5.13 <=
Check: /components/com_mailto/
Exploit: [Requires a valid user account] In com_mailto, it was possible to bypass timeout protection against sending automated emails.
Vulnerable? Yes
and lot of Vulnerable? No
these are yes what can i Do ? is it possible to hack this site ? to deface this site ?:headbash:
![[+]](https://sinister.li/images/modern/collapse_collapsed.png)