CVE-2007-6038
Joomla! com_juser 1.0.14 - RCE
Title source: llmDescription
PHP remote file inclusion vulnerability in xajax_functions.php in the JUser (com_juser) 1.0.14 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Exploits (1)
Scores
EPSS
0.1883
EPSS Percentile
95.2%
Classification
CWE
CWE-94
Status
draft
Affected Products (1)
joomlaequipment/juser
Timeline
Published
Nov 20, 2007
Tracked Since
Feb 18, 2026