CVE-2007-6555: Code Injection
Published Dec 28, 2007
·Updated
PHP remote file inclusion vulnerability in modules/modpxtlatest.php in the mosDirectory (comdirectory) 2.3.2 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfigabsolutepath] parameter.
Affected Software
1 affected component
Phil Taylor Mosdirectory=2.3.2
Event History
Dec 28, 2007
CVE Published
12:46 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6555?
CVE-2007-6555 is considered a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2007-6555?
To fix CVE-2007-6555, you should update the mosDirectory component for Joomla! to a version that is not vulnerable.
3
What software is affected by CVE-2007-6555?
CVE-2007-6555 affects the mosDirectory component version 2.3.2 for Joomla!.
4
What kind of attack is possible with CVE-2007-6555?
CVE-2007-6555 allows attackers to execute arbitrary PHP code on the server.
5
Is CVE-2007-6555 easily exploitable?
Yes, CVE-2007-6555 is easily exploitable by attackers with knowledge of the vulnerability.