CVE-2007-1702
Mambo Flatmenu < 1.7 - Remote File Inclusion via mosConfig_absolute_path Parameter
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1702. PoCs published by Cold Zero.
AI-analyzed exploit summary This exploit targets a remote file inclusion vulnerability in Mambo 4.5.1's Flatmenu module (version <= 1.07) by injecting a malicious URL parameter to execute arbitrary commands. It uses a GUI interface to facilitate the attack.
Description
PHP remote file inclusion vulnerability in mod_flatmenu.php in the Flatmenu 1.07 and earlier Mambo module allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Exploits (1)
This exploit targets a remote file inclusion vulnerability in Mambo 4.5.1's Flatmenu module (version <= 1.07) by injecting a malicious URL parameter to execute arbitrary commands. It uses a GUI interface to facilitate the attack.