CVE-2008-5053: Code Injection
Published Nov 13, 2008
·Updated
PHP remote file inclusion vulnerability in admin.rssreader.php in the Simple RSS Reader (comrssreader) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfiglivesite parameter.
Affected Software
2 affected components
Joomla Com Rssreader=1.0
Joomla joomla=1.0
Event History
Nov 13, 2008
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Data Sourced
11:30 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-5053?
CVE-2008-5053 is classified as a critical vulnerability, allowing remote code execution.
2
How can I fix CVE-2008-5053?
To fix CVE-2008-5053, upgrade to a patched version of the Simple RSS Reader component for Joomla!.
3
Which versions of Joomla! are affected by CVE-2008-5053?
CVE-2008-5053 specifically affects the Simple RSS Reader component version 1.0 on Joomla!.
4
What is the impact of exploiting CVE-2008-5053?
Exploiting CVE-2008-5053 allows attackers to execute arbitrary PHP code on the server.
5
Is there a way to mitigate the risk of CVE-2008-5053?
Mitigation of CVE-2008-5053 can be achieved by disabling the vulnerable component if upgrading is not immediately feasible.