CVE-2006-4858
mamboxchange serverstat_component < 0.4.4 - Remote Code Execution via mosConfig_absolute_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4858. PoCs published by Mehmet Ince.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in Mambo's com_serverstat component (version <=0.4.4). The vulnerability arises from insecure usage of the `mosConfig_absolute_path` parameter, allowing remote code execution by including malicious scripts.
Description
PHP remote file inclusion vulnerability in install.serverstat.php in the Serverstat (com_serverstat) 0.4.4 and earlier component for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in Mambo's com_serverstat component (version <=0.4.4). The vulnerability arises from insecure usage of the `mosConfig_absolute_path` parameter, allowing remote code execution by including malicious scripts.