38586vdb entry
http://osvdb.org/38586 CVE-2007-5362
Joomla! Component mosmedialite451 - Remote File Inclusion
Record summary
CVE-2007-5362 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) credits.html.php, (2) info.html.php, (3) media.divs.php, (4) media.divs.js.php, (5) purchase.html.php, or (6) support.html.php in includes/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: vector 3 may be the same as CVE-2007-2043.2.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBJoomla! Component mosmedialite451 - Remote File InclusionExploitDB exploitby k1n9k0ngNot analyzed1 file
References
638587vdb entry
http://osvdb.org/38587 38588vdb entry
http://osvdb.org/38588 25960vdb entry
http://www.securityfocus.com/bid/25960 mosmedialite451-mosconfig-file-include(37015)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/37015 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-5362