CVE-2007-6555
mosDirectory 2.3.2 - Remote Code Execution via GLOBALS[mosConfig_absolute_path] Parameter
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2007-6555. PoCs published by ShockShadow.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Joomla Component mosDirectory 2.3.2. The vulnerability allows an attacker to include a remote shell by manipulating the `GLOBALS[mosConfig_absolute_path]` parameter in the `mod_pxt_latest.php` file.
Description
PHP remote file inclusion vulnerability in modules/mod_pxt_latest.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Joomla Component mosDirectory 2.3.2. The vulnerability allows an attacker to include a remote shell by manipulating the `GLOBALS[mosConfig_absolute_path]` parameter in the `mod_pxt_latest.php` file.