1447Third-party advisory
http://securityreason.com/securityalert/1447 CVE-2006-4348
Joomla! Component Kochsuite 0.9.4 - Remote File Inclusion
Record summary
CVE-2006-4348 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
PHP remote file inclusion vulnerability in config.kochsuite.php in the Kochsuite (com_kochsuite) 0.9.4 component for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBJoomla! Component Kochsuite 0.9.4 - Remote File InclusionExploitDB exploitby caminoNot analyzed1 file
References
728098vdb entry
http://www.osvdb.org/28098 20060818 Joomla Kochsuite Component <= 0.9.4 (config.kochsuite.php) Remote File Inclusion Vulnerabilitymailing list
http://www.securityfocus.com/archive/1/443703/100/0/threaded 19590vdb entry
http://www.securityfocus.com/bid/19590 kochsuite-config-file-include(28457)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/28457 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-4348 2215exploit
https://www.exploit-db.com/exploits/2215