CVE-2008-5789

Joomla! Recly Interactive Feederator 1.0.5 - RCE

Title source: llm

Description

Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (com_feederator) component 1.0.5 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) mosConfig_absolute_path parameter to (a) add_tmsp.php, (b) edit_tmsp.php and (c) tmsp.php in includes/tmsp/; and the (2) GLOBALS[mosConfig_absolute_path] parameter to (d) includes/tmsp/subscription.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by NoGe · textwebappsphp
https://www.exploit-db.com/exploits/7040

Scores

EPSS 0.0516
EPSS Percentile 89.7%

Classification

CWE
CWE-94
Status draft

Affected Products (1)

recly/interactive_feederator

Timeline

Published Dec 31, 2008
Tracked Since Feb 18, 2026