CVE-2009-1822
InterJoomla ArtForms 2.1b7 - Remote Code Execution via mosConfig_absolute_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1822. PoCs published by iskorpitx.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in ArtForms 2.1b7 by manipulating the 'mosConfig_absolute_path' parameter in multiple PHP scripts to include a remote shell.
Description
Multiple PHP remote file inclusion vulnerabilities in the InterJoomla ArtForms (com_artforms) component 2.1b7 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) imgcaptcha.php or (2) mp3captcha.php in assets/captcha/includes/captchaform/, or (3) assets/captcha/includes/captchatalk/swfmovie.php.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in ArtForms 2.1b7 by manipulating the 'mosConfig_absolute_path' parameter in multiple PHP scripts to include a remote shell.