CVE-2007-2196: Medium severity Joomla jambook vulnerability
DISPUTED PHP remote file inclusion vulnerability in jambook.php in the Jambook (comJambook) 1.0 beta7 module for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter. NOTE: this issue has been disputed by a reliable third party because the jambook.php protects against direct request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2196?
The severity of CVE-2007-2196 is considered significant due to the potential for remote code execution.
How do I fix CVE-2007-2196?
To fix CVE-2007-2196, upgrade the Jambook module to a secure version or implement input validation to sanitize the mosConfig_absolute_path parameter.
What versions are affected by CVE-2007-2196?
CVE-2007-2196 affects Jambook version 1.0 beta 7 for both Joomla and Mambo.
What kind of attack can exploit CVE-2007-2196?
CVE-2007-2196 can be exploited through remote file inclusion attacks allowing arbitrary PHP code execution.
Is CVE-2007-2196 still a concern in modern applications?
While CVE-2007-2196 is an older vulnerability, it remains a concern if outdated versions of Jambook are still in use.