CVE-2008-6221

Dadamailproject Dada Mail Manager - Code Injection

Title source: rule

Description

PHP remote file inclusion vulnerability in config.dadamail.php in the Dada Mail Manager (com_dadamail) component 2.6 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by NoGe · textwebappsphp
https://www.exploit-db.com/exploits/7002

Scores

EPSS 0.8280
EPSS Percentile 99.2%

Details

CWE
CWE-94
Status published
Products (1)
dadamailproject/dada_mail_manager 2.6
Published Feb 20, 2009
Tracked Since Feb 18, 2026