CVE-2009-4431
com_jcalpro 1.5.3.6 - Remote Code Execution via mosConfig_absolute_path Parameter
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4431. PoCs published by kaMtiEz.
AI-analyzed exploit summary This is a writeup describing a local file inclusion (LFI) vulnerability in the JCalPro component for Joomla. The vulnerability allows an attacker to include arbitrary files via the 'mosConfig_absolute_path' parameter in 'cal_popup.php'.
Description
PHP remote file inclusion vulnerability in cal_popup.php in the Anything Digital Development JCal Pro (aka com_jcalpro or JCP) component 1.5.3.6 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Exploits (1)
This is a writeup describing a local file inclusion (LFI) vulnerability in the JCalPro component for Joomla. The vulnerability allows an attacker to include arbitrary files via the 'mosConfig_absolute_path' parameter in 'cal_popup.php'.