CVE-2006-3949
Mambo Artlinks Component - Remote Code Execution via mosConfig_absolute_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-3949. PoCs published by camino.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Artlinks v1.0 Beta 4, a Mambo/Joomla CMS component. The vulnerability allows an attacker to include arbitrary remote files via the `mosConfig_absolute_path` parameter in `artlinks.dispnew.php`.
Description
PHP remote file inclusion vulnerability in artlinks.dispnew.php in the Artlinks component (com_artlinks) for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Artlinks v1.0 Beta 4, a Mambo/Joomla CMS component. The vulnerability allows an attacker to include arbitrary remote files via the `mosConfig_absolute_path` parameter in `artlinks.dispnew.php`.