CVE-2008-2990: Code Injection
Published Jul 2, 2008
·Updated
PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (comfacileforms) component 1.4.4 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the ffcompath parameter.
Affected Software
3 affected components
Mambo Com Facileforms=1.4.4
Joomla joomla
Joomla Com Facileforms=1.4.4
Event History
Jul 2, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2990?
CVE-2008-2990 has a moderate severity level due to its potential for remote code execution.
2
How do I fix CVE-2008-2990?
To fix CVE-2008-2990, update the FacileForms component to the latest version that is not affected by this vulnerability.
3
What systems are impacted by CVE-2008-2990?
CVE-2008-2990 affects FacileForms 1.4.4 for Mambo and Joomla! systems.
4
What type of attack does CVE-2008-2990 enable?
CVE-2008-2990 enables remote attackers to execute arbitrary PHP code on vulnerable systems.
5
Is CVE-2008-2990 easy to exploit?
CVE-2008-2990 is considered relatively easy to exploit due to its reliance on user-controllable parameters.