CVE-2007-2144
JoomlaPack 1.0.4a2 RE - Remote Code Execution via mosConfig_absolute_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2144. PoCs published by Cold Zero.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in JoomlaPack 1.0.4a2 via the 'mosConfig_absolute_path' parameter in CAltInstaller.php. The attacker can include a remote file (e.g., r57.txt) to execute arbitrary code.
Description
PHP remote file inclusion vulnerability in includes/CAltInstaller.php in the JoomlaPack (com_jpack) 1.0.4a2 RE component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in JoomlaPack 1.0.4a2 via the 'mosConfig_absolute_path' parameter in CAltInstaller.php. The attacker can include a remote file (e.g., r57.txt) to execute arbitrary code.