NASLDB: Acajoom Component for Joomla! <= 3.2.6 Backdoor Detection
General
ID: 39482
Name: Acajoom Component for Joomla! <= 3.2.6 Backdoor Detection
Summary: Tries to execute a command
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS Temporal Vector: CVSS2#E:F/RL:OF/RC:C
Port: 80
Family: CGI abuses
Type: Remote
Description
The remote host is running Acajoom, a third-party component for
Joomla! for managing mailing lists, newsletters, auto-responders, and
other sorts of communications.
The version of Acajoom installed on the remote host reportedly
contains a backdoor in the ‘self.acajoom.php’ script. By calling this
script and setting the ‘lang’ parameter to ‘en-g’, an unauthenticated
remote attacker can pass arbitrary input via the ‘s’ parameter to an
‘eval()’ call, to be executed subject to the privileges of the web
server user id.
Note that there is also reported another backdoor involving the
‘GetBots()’ function in ‘install.acajoom.php’, which emails
information to an address in Russian when the component is installed,
although Nessus has not checked for it.
Exploiting
Exploit Available: True
Exploitability Ease: Exploits are available
Sources
CVE: –
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: –
Patch Release: –
Plugin Release: 2009/06/23
Plugin
Version: 1.11
Filename: acajoom_3_2_6_backdoor.nasl
Filesize: 5029 bytes
MD5 Hash: edfc43c443699f45f616376226cd108b
Identification: Host/OS
Require Keys: www/joomla
Dependencies: "joomla_detect.nasl", "os_fingerprint.nasl"
Copyright: This script is Copyright© 2009-2011 Tenable Network Security, Inc.
- Latest Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













