CVE-2007-5389: Code Injection
DISPUTED PHP remote file inclusion vulnerability in preview.php in the swMenuFree (comswmenufree) 4.6 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter. NOTE: a reliable third party disputes this issue because preview.php tests a certain constant to prevent direct requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5389?
CVE-2007-5389 is classified as a remote file inclusion vulnerability, which can lead to the execution of arbitrary PHP code.
How do I fix CVE-2007-5389?
To fix CVE-2007-5389, update the swMenuFree component to a version that does not have this vulnerability.
What software is affected by CVE-2007-5389?
CVE-2007-5389 affects the swMenuFree component version 4.6 for Joomla!
Can CVE-2007-5389 be exploited without authentication?
Yes, CVE-2007-5389 can potentially be exploited by remote attackers without requiring authentication.
Is there any mitigation available for CVE-2007-5389?
Mitigations for CVE-2007-5389 include disabling the swMenuFree component or applying security patches as they become available.