CVE-2008-6841
gmitc com_dbquery < 1.4.1.1 - Remote Code Execution via mosConfig_absolute_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6841. PoCs published by SsEs.
AI-analyzed exploit summary This is a writeup describing a remote file inclusion vulnerability in Joomla's DBQuery component (CVE-2008-6841). The vulnerability arises from improper handling of the `mosConfig_absolute_path` parameter in `common.class.php`.
Description
PHP remote file inclusion vulnerability in the Green Mountain Information Technology and Consulting Database Query (com_dbquery) component 1.4.1.1 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to classes/DBQ/admin/common.class.php.
Exploits (1)
This is a writeup describing a remote file inclusion vulnerability in Joomla's DBQuery component (CVE-2008-6841). The vulnerability arises from improper handling of the `mosConfig_absolute_path` parameter in `common.class.php`.