CVE-2006-3748
LoudMouth Component for Mambo - Remote Code Execution via mosConfig_absolute_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-3748. PoCs published by h4ntu.
AI-analyzed exploit summary This is a writeup describing a remote file inclusion vulnerability in the Mambo CMS component 'com_loudmouth'. The vulnerability allows an attacker to include arbitrary files by manipulating the 'mosConfig_absolute_path' parameter.
Description
PHP remote file inclusion vulnerability in includes/abbc/abbc.class.php in the LoudMouth Component for Mambo 4.0j, and possibly other versions including 4.1, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Exploits (1)
This is a writeup describing a remote file inclusion vulnerability in the Mambo CMS component 'com_loudmouth'. The vulnerability allows an attacker to include arbitrary files by manipulating the 'mosConfig_absolute_path' parameter.