CVE-2006-3750
Hashcash Component for Joomla! 1.2.1 - Remote Code Execution via mosConfig_absolute_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-3750. PoCs published by Matdhule.
AI-analyzed exploit summary This exploit leverages a file inclusion vulnerability in the com_hashcash component for Joomla, allowing remote attackers to include arbitrary files via the mosConfig_absolute_path parameter. The PoC demonstrates remote code execution by including a malicious file from an attacker-controlled server.
Description
PHP remote file inclusion vulnerability in server.php in the Hashcash Component (com_hashcash) 1.2.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Exploits (1)
This exploit leverages a file inclusion vulnerability in the com_hashcash component for Joomla, allowing remote attackers to include arbitrary files via the mosConfig_absolute_path parameter. The PoC demonstrates remote code execution by including a malicious file from an attacker-controlled server.