First published: Tue Mar 27 2007(Updated: )
Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to ImageManager/Classes/ImageManager.php under the (1) components/ or (2) administrator/components/ directory trees.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Swmenu Component | =4.0 | |
Joomla Swmenu Component | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1699 has a high severity rating as it allows remote attackers to execute arbitrary PHP code.
To fix CVE-2007-1699, update to the latest version of the SWmenu component for Mambo or Joomla to mitigate the vulnerabilities.
CVE-2007-1699 affects the SWmenu component version 4.0 for both Joomla and Mambo.
Yes, CVE-2007-1699 can lead to data breaches as it allows attackers to execute arbitrary PHP code on vulnerable systems.
Yes, there are patches available in newer versions of the SWmenu component that address the vulnerabilities in CVE-2007-1699.