CVE-2007-2089
Jx Development Article Component < 1.1 - Remote File Inclusion via absolute_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2089. PoCs published by Cold Zero.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in the Mambo/Joomla Component New Article Component <= 1.1. The vulnerability allows an attacker to include arbitrary remote files via the 'absolute_path' parameter in two different PHP files.
Description
Multiple PHP remote file inclusion vulnerabilities in the Jx Development Article 1.1 and earlier component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to com_articles.php in (1) components/ or (2) classes/html/.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in the Mambo/Joomla Component New Article Component <= 1.1. The vulnerability allows an attacker to include arbitrary remote files via the 'absolute_path' parameter in two different PHP files.