First published: Tue Sep 18 2007(Updated: )
PHP remote file inclusion vulnerability in admin.joomlaflashfun.php in the Flash Fun! (com_joomlaflashfun) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Flash Fun Component | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4955 is classified as a critical severity vulnerability due to its potential for arbitrary code execution.
To fix CVE-2007-4955, upgrade to a patched version of the Joomla Flash Fun component or disable the affected component.
CVE-2007-4955 is associated with remote file inclusion attacks that can lead to arbitrary code execution.
CVE-2007-4955 affects the Flash Fun! component version 1.0 for Joomla.
Yes, if your website is using the vulnerable version of the Joomla Flash Fun component, it is at risk of exploitation.