CVE-2006-4241
Mambo Reporter Component - Remote File Inclusion Code Execution
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4241. PoCs published by Crackers_Child.
AI-analyzed exploit summary The code describes a remote file inclusion vulnerability in the Reporter component of Mambo CMS due to improper input sanitization. An attacker can exploit this by injecting a malicious URL parameter to execute arbitrary PHP code.
Description
PHP remote file inclusion vulnerability in processor/reporter.sql.php in the Reporter Mambo component (com_reporter) allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Exploits (1)
The code describes a remote file inclusion vulnerability in the Reporter component of Mambo CMS due to improper input sanitization. An attacker can exploit this by injecting a malicious URL parameter to execute arbitrary PHP code.