CVE-2009-2634
MediaLibrary (com_media_library) 1.5.3 Basic - Remote Code Execution via mosConfig_absolute_path Parameter
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2634. PoCs published by Mehmet Ince.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in Joomla's com_media_library component (version 1.5.3) by manipulating the 'mosConfig_absolute_path' parameter to include a remote shell. The exploit is straightforward and relies on a single HTTP request.
Description
PHP remote file inclusion vulnerability in toolbar_ext.php in the MediaLibrary (com_media_library) component 1.5.3 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in Joomla's com_media_library component (version 1.5.3) by manipulating the 'mosConfig_absolute_path' parameter to include a remote shell. The exploit is straightforward and relies on a single HTTP request.