First published: Wed Jul 02 2008(Updated: )
PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the ff_compath parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla com facileforms | =1.4.4 | |
Joomla | ||
Mambo CMS FacileForms | =1.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2990 has a moderate severity level due to its potential for remote code execution.
To fix CVE-2008-2990, update the FacileForms component to the latest version that is not affected by this vulnerability.
CVE-2008-2990 affects FacileForms 1.4.4 for Mambo and Joomla! systems.
CVE-2008-2990 enables remote attackers to execute arbitrary PHP code on vulnerable systems.
CVE-2008-2990 is considered relatively easy to exploit due to its reliance on user-controllable parameters.