lunes, 15 de marzo de 2010 | Online desde el 2005
 
 
hosting joomlaspanish
ExtCalendar | File Inclusion Vulnerability PDF Imprimir E-Mail

ExtCalendar Module for Mambo/Joomla "mosConfig_absolute_path" File Inclusion Vulnerability
Advisory ID : FrSIRT/ADV-2006-2711
CVE ID : GENERIC-MAP-NOMATCH
Rated as : High Risk
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2006-07-09

Technical Description
A vulnerability has been identified in ExtCalendar (module for Mambo/Joomla), which may be exploited by attackers to execute arbitrary commands. This flaw is due to an input validation error in the "extcalendar.php" script that fails to validate the "mosConfig_absolute_path" parameter, which could be exploited by remote attackers to include malicious files and execute arbitrary commands with the privileges of the web server.

Affected Products
ExtCalendar (module for Mambo/Joomla) version 0.9.1 and prior

Solución al "mosConfig_absolute_path" File Inclusion Issue


 
< Anterior   Siguiente >