CVE-2007-2005 Information
Description
Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) contact_type.php (2) itemstatus_type.php (3) projectstatus_type.php (4) request_type.php (5) responses_type.php (6) timelog_type.php or (7) urgency_type.php in inc/.
Reference
http://attrition.org/pipermail/vim/2007-April/001504.html http://www.osvdb.org/34795 http://www.osvdb.org/34796 http://www.osvdb.org/34797 http://www.osvdb.org/34798 http://www.osvdb.org/34799 http://www.osvdb.org/34800 http://www.osvdb.org/34801 http://www.securityfocus.com/bid/23408 http://www.vupen.com/english/advisories/2007/1346 https://exchange.xforce.ibmcloud.com/vulnerabilities/33552 https://www.exploit-db.com/exploits/3703
Share on: