CVE-2008-6347
Onguma Time Sheet 2.0 4b - Remote Code Execution via mosConfig_absolute_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6347. PoCs published by NoGe.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in com_ongumatimesheet20 version 4 Beta. The vulnerability arises from improper input validation in the 'mosConfig_absolute_path' parameter, allowing an attacker to include arbitrary remote files.
Description
PHP remote file inclusion vulnerability in lib/onguma.class.php in the Onguma Time Sheet (com_ongumatimesheet20) 2.0 4b component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in com_ongumatimesheet20 version 4 Beta. The vulnerability arises from improper input validation in the 'mosConfig_absolute_path' parameter, allowing an attacker to include arbitrary remote files.