6.8
CVSSv2

CVE-2006-4553

Published: 06/09/2006 Updated: 17/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in plugin.class.php in the com_comprofiler Components 1.0 RC2 for Mambo and Joomla! allows remote malicious users to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

joomla com comprofiler component 1.0_rc2

mambo com comprofiler component 1.0_rc2

Exploits

source: wwwsecurityfocuscom/bid/19725/info The Mambo and Joomla com_comprofiler component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webser ...