First published: Thu Mar 22 2007(Updated: )
Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) components/com_nfn_addressbook/nfnaddressbook.php or (2) administrator/components/com_nfn_addressbook/nfnaddressbook.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Nfn Address Book | =0.4 | |
Mambo Nfn Address Book | =0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1596 has a medium severity level due to the potential for remote code execution.
To fix CVE-2007-1596, you should update the NFN Address Book component to a version that is not vulnerable to remote file inclusion issues.
CVE-2007-1596 affects Joomla and Mambo installations that use the NFN Address Book version 0.4.
The main risks associated with CVE-2007-1596 include unauthorized remote code execution and potential data compromise.
An attacker can exploit CVE-2007-1596 by supplying a malicious URL through the mosConfig_absolute_path parameter, allowing them to execute arbitrary PHP code.