RETIRED: Joomla OpenSEF Component mosConfig_absolute_path Remote File Include Vulnerability
BID:19600
CVE-2006-4320 |Info
RETIRED: Joomla OpenSEF Component mosConfig_absolute_path Remote File Include Vulnerability
| Bugtraq ID: | 19600 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 19 2006 12:00AM |
| Updated: | Aug 24 2006 07:34PM |
| Credit: | Discovery is credited to [email protected]. |
| Vulnerable: |
OpenSEF Project OpenSEF 2.0-beta3 OpenSEF Project OpenSEF 2.0 RC5 SP2 OpenSEF Project OpenSEF 2.0 RC5 SP1 OpenSEF Project OpenSEF 2.0 RC5 OpenSEF Project OpenSEF 2.0 RC4 OpenSEF Project OpenSEF 2.0 RC3 OpenSEF Project OpenSEF 2.0 RC2 OpenSEF Project OpenSEF 2.0 RC1 |
| Not Vulnerable: | |
Discussion
RETIRED: Joomla OpenSEF Component mosConfig_absolute_path Remote File Include Vulnerability
The Joomla OpenSEF component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
This BID has been retired because this issue is not exploitable.
The Joomla OpenSEF component is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
This BID has been retired because this issue is not exploitable.
Exploit / POC
RETIRED: Joomla OpenSEF Component mosConfig_absolute_path Remote File Include Vulnerability
Attackers can exploit this issue using a web client.
Attackers can exploit this issue using a web client.
Solution / Fix
RETIRED: Joomla OpenSEF Component mosConfig_absolute_path Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
RETIRED: Joomla OpenSEF Component mosConfig_absolute_path Remote File Include Vulnerability
References:
References:
- OpenSEF Homepage (OpenSEF Project)
- Modification For OpenSEF Remote file Inclusion ([email protected])