CVE-2006-3995
User Home Pages 0.5 - Remote Code Execution via mosConfig_absolute_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-3995. PoCs published by Kurdish Security.
AI-analyzed exploit summary This exploit targets a file inclusion vulnerability in RavensPortal's User Home Pages (UHP) component. It allows remote attackers to include arbitrary files via the `mosConfig_absolute_path` parameter, leading to remote code execution.
Description
Multiple PHP remote file inclusion vulnerabilities in (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php, (4) install.uhp.php, (5) toolbar.uhp.html.php, (6) uhp.class.php, and (7) uninstall.uhp.php, in the UHP (User Home Pages) 0.5 component (aka com_uhp) for Mambo or Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Exploits (1)
This exploit targets a file inclusion vulnerability in RavensPortal's User Home Pages (UHP) component. It allows remote attackers to include arbitrary files via the `mosConfig_absolute_path` parameter, leading to remote code execution.